QID 377972
Date Published: 2023-06-08
QID 377972: Trend Micro Apex One (On-Prem) Multiple Vulnerabilities (000290464)
Trend Micro Apex One protection offers advanced automated threat detection and response against an ever-growing variety of threats, including file-less and ransomware.
CVE-2022-24678: Trend Micro Apex One Security Agent Resource Exhaustion Denial-of-Service Vulnerability
CVE-2022-24679: Trend Micro Apex One Security Agent Link Following Local Privilege Escalation Vulnerability.
CVE-2022-24680: Trend Micro Apex One Security Agent Link Following Local Privilege Escalation Vulnerability.
Note: An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Versions:
Trend Micro Apex One 2019 (On-Prem) prior to build 10071
QID Detection Logic:(Authenticated):
This QID checks for vulnerable version of Trend Micro Apex by fetching the version from registry
Successful exploitation of the vulnerability may allow a local attacker to escalate privileges on and modify files.
CVEs related to QID 377972
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 000290464 |
|