Lucene search

K
nvd[email protected]NVD:CVE-2022-36336
HistoryJul 30, 2022 - 12:15 a.m.

CVE-2022-36336

2022-07-3000:15:08
CWE-59
web.nvd.nist.gov
3
vulnerability
trend micro
apex one
worry-free business security
local attacker
escalate privileges
activeupdate
spyware pattern

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.9%

A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been deployed automatically via ActiveUpdate to customers in an updated Spyware pattern. Customers who are up-to-date on detection patterns are not required to take any additional steps to mitigate this issue.

Affected configurations

Nvd
Node
trendmicroapex_oneMatch-saas
OR
trendmicroapex_oneMatch2019
OR
trendmicroworry-free_business_securityMatch10.0sp1
OR
trendmicroworry-free_business_security_servicesMatch-saas
AND
microsoftwindowsMatch-
VendorProductVersionCPE
trendmicroapex_one-cpe:2.3:a:trendmicro:apex_one:-:*:*:*:saas:*:*:*
trendmicroapex_one2019cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
trendmicroworry-free_business_security10.0cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*
trendmicroworry-free_business_security_services-cpe:2.3:a:trendmicro:worry-free_business_security_services:-:*:*:*:saas:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.9%

Related for NVD:CVE-2022-36336