QID 378531

Date Published: 2023-06-01

QID 378531: Trend Micro Deep Security 20 and Cloud One Local Privilege Escalation Vulnerability

Trend Micro Deep Security provides advanced server security for physical, virtual, and cloud servers. It protects enterprise applications and data from breaches and business disruptions without requiring emergency patching.

CVE-2022-40710: A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations.

CVE-2022-40707 through 2022-40709: Out-of-bounds read vulnerabilities in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations.

Affected versions:
Versions 20 of the Trend Micro Deep Security Agent for Windows only.
QID Detection Logic(Authenticated):
This QID checks for vulnerable version of Trend Micro Deep Security Agent by checking the file version

On successful exploitation the attacker may be able to elevate the privileges impacting confidentiality, integrity, and availability.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Upgrade Trend Micro Deep Security Agent to latest version. For further details refer to Trend Micro's Security Advisory . You can download the latest version from Trend Micro's Deep Security .

    CVEs related to QID 378531

    Software Advisories
    Advisory ID Software Component Link
    000291590 URL Logo success.trendmicro.com/dcx/s/solution/000291590?language=en_US