PT-2024-5767 · Trend Micro · Trend Micro Vpn+1
Hashim Jawad
+1
·
Published
2024-02-02
·
Updated
2025-07-31
·
CVE-2024-41183
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro VPN versions 5.8.1012 and below
Trend Micro VPN Proxy One Pro (affected versions not specified)
Description
The issue is related to incorrect link resolution before accessing a file in the DEP Manager component of Trend Micro VPN Proxy One Pro for Windows. This can allow an attacker to elevate their privileges under specific conditions. The vulnerability may lead to arbitrary file overwrite, resulting in privilege escalation.
Recommendations
For Trend Micro VPN versions 5.8.1012 and below, update to a version above 5.8.1012 to resolve the issue.
For Trend Micro VPN Proxy One Pro, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Vpn
Trend Micro Vpn Proxy One Pro