ZDI-CAN-29830: ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro VPN. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-67212.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29830?
ZDI-CAN-29830 has been assigned a CVSS rating of 7.0, indicating a high severity level.
How do I fix ZDI-CAN-29830?
To mitigate ZDI-CAN-29830, ensure that Trend Micro VPN is updated to the latest version provided by the vendor.
Who is affected by ZDI-CAN-29830?
Users of Trend Micro VPN with vulnerable OpenSSL configurations are potentially affected by ZDI-CAN-29830.
What type of attack does ZDI-CAN-29830 facilitate?
ZDI-CAN-29830 allows local attackers to escalate privileges on affected installations of Trend Micro VPN.
What conditions must be met to exploit ZDI-CAN-29830?
An attacker must first gain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-29830.