PT-2022-17786 · Trend Micro · Trend Micro Portable Security
Published
2022-03-08
·
Updated
2022-03-19
·
CVE-2022-26319
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Trend Micro Portable Security versions 2.0 through 3.0 Pro
Description
An installer search patch element vulnerability could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. The attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this issue.
Recommendations
For Trend Micro Portable Security versions 2.0 through 3.0 Pro, consider restricting access to the installer folder to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the vulnerable installer search patch element functionality until the issue is resolved.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Portable Security