PT-2022-25487 · Trend Micro · Cloud One - Workload Security Agent For Windows+1

Abdelhamid Naceri

·

Published

2022-09-23

·

Updated

2024-02-27

·

CVE-2022-40710

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Deep Security version 20 Cloud One - Workload Security Agent for Windows (affected versions not specified)
Description A link following issue could allow a local attacker to escalate privileges on affected installations. The attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this issue.
Recommendations For Trend Micro Deep Security version 20, update to a version that includes a fix for this issue. For Cloud One - Workload Security Agent for Windows, apply the recommended configuration changes or patches as soon as they become available to prevent privilege escalation. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2022-40710
ZDI-22-1296

Affected Products

Cloud One - Workload Security Agent For Windows
Trend Micro Deep Security