PT-2023-8405 · Microsoft+1 · Windows+2
Published
2023-09-07
·
Updated
2024-07-03
·
CVE-2023-52338
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Deep Security versions 20.0
Trend Micro Cloud One - Endpoint and Workload Security Agent (affected versions not specified)
Description
The issue is related to a link following vulnerability in the Anti-Malware module of Trend Micro Deep Security Agent for Windows operating systems. This vulnerability is caused by incorrect handling of symbolic links before accessing a file. Exploitation of this issue could allow an attacker to escalate privileges and execute arbitrary code. To exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system.
Recommendations
For Trend Micro Deep Security version 20.0, update to a version that includes the fix for this issue.
For Trend Micro Cloud One - Endpoint and Workload Security Agent, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Cloud One - Endpoint/Workload Security Agent
Trend Micro Deep Security
Windows