PT-2022-17786 · Trend Micro · Trend Micro Portable Security

Published

2022-03-08

·

Updated

2022-03-19

·

CVE-2022-26319

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro Portable Security versions 2.0 through 3.0 Pro
Description An installer search patch element vulnerability could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. The attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this issue.
Recommendations For Trend Micro Portable Security versions 2.0 through 3.0 Pro, consider restricting access to the installer folder to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the vulnerable installer search patch element functionality until the issue is resolved.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26319

Affected Products

Trend Micro Portable Security