Lucene search

K
zdiNT AUTHORITY\ANONYMOUS LOGONZDI-23-1621
HistoryNov 14, 2023 - 12:00 a.m.

Trend Micro Apex One Local File Inclusion Local Privilege Escalation Vulnerability

2023-11-1400:00:00
NT AUTHORITY\ANONYMOUS LOGON
www.zerodayinitiative.com
8
trend micro
apex one
file inclusion
privilege escalation
vulnerability
web console
php
iusr
arbitrary code

AI Score

7.7

Confidence

High

EPSS

0

Percentile

15.9%

This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Apex One web console. The issue results from passing an insecure path to a PHP include function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of IUSR.

AI Score

7.7

Confidence

High

EPSS

0

Percentile

15.9%

Related for ZDI-23-1621