ZDI-CAN-16303: Trend Micro Proxy One Pro Incorrect Permission Assignment Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Proxy One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from incorrect permissions set on a directory. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-16303?
The severity of ZDI-CAN-16303 is classified as high due to its potential to allow local privilege escalation.
How do I fix ZDI-CAN-16303?
To fix ZDI-CAN-16303, update Trend Micro Proxy One Pro to the latest version provided by Trend Micro.
Who is affected by ZDI-CAN-16303?
ZDI-CAN-16303 affects installations of Trend Micro Proxy One Pro that have not been patched.
Can ZDI-CAN-16303 be exploited remotely?
No, ZDI-CAN-16303 requires local access to the system to exploit the vulnerability.
What type of attack does ZDI-CAN-16303 involve?
ZDI-CAN-16303 involves a local privilege escalation attack that can be executed by an attacker with low-privileged code access.