PT-2023-23855 · Trend Micro · Trend Micro Mobile Security
Poh Jia Hao
·
Published
2023-05-12
·
Updated
2023-06-30
·
CVE-2023-32524
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Mobile Security (Enterprise) version 9.8 SP5
Description
The issue allows a remote user to bypass authentication, potentially chaining with other vulnerabilities. An attacker must first obtain the ability to execute low-privileged code on the target system to exploit this issue.
Recommendations
For Trend Micro Mobile Security (Enterprise) version 9.8 SP5, consider restricting access to the widgets that allow authentication bypass until a patch is available. As a temporary workaround, review and strengthen the overall system security to prevent low-privileged code execution on the target system. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Mobile Security