PT-2022-16795 · Trend Micro · Trend Micro Worry-Free Business Security Services+3
Elias Martinez
+1
·
Published
2022-02-16
·
Updated
2022-03-03
·
CVE-2022-24678
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Apex One (affected versions not specified)
Trend Micro Apex One as a Service (affected versions not specified)
Trend Micro Worry-Free Business Security 10.0 SP1
Trend Micro Worry-Free Business Security Services (affected versions not specified)
Description
A security agent resource exhaustion denial-of-service issue could allow an attacker to flood a temporary log location and consume all disk space on affected installations.
Recommendations
For Trend Micro Apex One, consider restricting access to temporary log locations to minimize the risk of exploitation.
For Trend Micro Apex One as a Service, consider implementing measures to limit disk space consumption.
For Trend Micro Worry-Free Business Security 10.0 SP1, restrict access to vulnerable components until a fix is available.
For Trend Micro Worry-Free Business Security Services, avoid configurations that could lead to resource exhaustion until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Apex One
Trend Micro Apex One As A Service
Trend Micro Worry-Free Business Security 10.0 Sp1
Trend Micro Worry-Free Business Security Services