PT-2022-26052 · Trend Micro · Trend Micro Apex One

Elias Martinez

+1

·

Published

2022-10-07

·

Updated

2022-10-11

·

CVE-2022-41746

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Apex One (affected versions not specified)
Description A forced browsing issue could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. The attacker must first obtain the ability to log onto the Apex One web console in order to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-41746
ZDI-22-1403

Affected Products

Trend Micro Apex One