PT-2024-1407 · Trend Micro · Uiairsupport

Renato Garreton

·

Published

2024-01-24

·

Updated

2024-02-06

·

CVE-2024-23940

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro uiAirSupport versions 6.0.2092 and below
Description The issue is related to a DLL hijacking/proxying vulnerability in the Trend Micro uiAirSupport component. If exploited, this could allow an attacker to impersonate and modify a library, execute code on the system, and ultimately escalate privileges on an affected system. The vulnerability is associated with the loading of untrusted DLL libraries, which may enable an attacker to read, modify, or delete data, execute arbitrary code, and elevate their privileges.
Recommendations For versions 6.0.2092 and below, consider disabling the vulnerable DLL loading functionality as a temporary workaround until a patch is available. Restrict access to the uiAirSupport component to minimize the risk of exploitation. Avoid using potentially vulnerable libraries in the affected system until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-00876
CVE-2024-23940

Affected Products

Uiairsupport