ZDI-24-585: Trend Micro VPN Proxy One Pro Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro VPN Proxy One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Vpn Background Controller. By creating a symbolic link, an attacker can abuse the application to create a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro VPN Proxy One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2024-36473.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-585?
ZDI-24-585 has been categorized as a denial-of-service vulnerability, which can impact availability.
How do I fix ZDI-24-585?
To mitigate ZDI-24-585, ensure that your Trend Micro VPN Proxy One Pro is updated to the latest version provided by the vendor.
Who is affected by ZDI-24-585?
ZDI-24-585 affects installations of Trend Micro VPN Proxy One Pro that allow local execution of low-privileged code.
Can ZDI-24-585 be exploited remotely?
No, ZDI-24-585 requires local access to the system to exploit the denial-of-service condition.
What type of attacks does ZDI-24-585 facilitate?
ZDI-24-585 allows local attackers to create a denial-of-service condition on the affected installations.