First published: Thu Jun 06 2024(Updated: )
This vulnerability allows local attackers to disclose sensitive information on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the VsApiNT module. By creating a mount point, an attacker can abuse the agent to disclose the contents of a file. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM.
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Apex One |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-CAN-22032 is classified as a medium severity vulnerability.
To fix ZDI-CAN-22032, update your Trend Micro Apex One Security Agent to the latest version provided by Trend Micro.
ZDI-CAN-22032 allows local attackers to disclose sensitive information from affected installations.
An attacker must have the ability to execute low-privileged code on the target system to exploit ZDI-CAN-22032.
ZDI-CAN-22032 affects Trend Micro Apex One Security Agent installations.