PT-2024-5767 · Trend Micro · Trend Micro Vpn+1

Hashim Jawad

+1

·

Published

2024-02-02

·

Updated

2025-07-31

·

CVE-2024-41183

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro VPN versions 5.8.1012 and below Trend Micro VPN Proxy One Pro (affected versions not specified)
Description The issue is related to incorrect link resolution before accessing a file in the DEP Manager component of Trend Micro VPN Proxy One Pro for Windows. This can allow an attacker to elevate their privileges under specific conditions. The vulnerability may lead to arbitrary file overwrite, resulting in privilege escalation.
Recommendations For Trend Micro VPN versions 5.8.1012 and below, update to a version above 5.8.1012 to resolve the issue. For Trend Micro VPN Proxy One Pro, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

LPE

Link Following

Weakness Enumeration

Related Identifiers

BDU:2024-06480
CVE-2024-41183
ZDI-24-1022
ZDI-24-1023

Affected Products

Trend Micro Vpn
Trend Micro Vpn Proxy One Pro