PT-2024-1407 · Trend Micro · Uiairsupport
Renato Garreton
·
Published
2024-01-24
·
Updated
2024-02-06
·
CVE-2024-23940
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro uiAirSupport versions 6.0.2092 and below
Description
The issue is related to a DLL hijacking/proxying vulnerability in the Trend Micro uiAirSupport component. If exploited, this could allow an attacker to impersonate and modify a library, execute code on the system, and ultimately escalate privileges on an affected system. The vulnerability is associated with the loading of untrusted DLL libraries, which may enable an attacker to read, modify, or delete data, execute arbitrary code, and elevate their privileges.
Recommendations
For versions 6.0.2092 and below, consider disabling the vulnerable DLL loading functionality as a temporary workaround until a patch is available. Restrict access to the uiAirSupport component to minimize the risk of exploitation. Avoid using potentially vulnerable libraries in the affected system until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Untrusted Search Path
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Uiairsupport