QID 378531
Date Published: 2023-06-01
QID 378531: Trend Micro Deep Security 20 and Cloud One Local Privilege Escalation Vulnerability
Trend Micro Deep Security provides advanced server security for physical, virtual, and cloud servers. It protects enterprise applications and data from breaches and business disruptions without requiring emergency patching.
CVE-2022-40710: A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations.
CVE-2022-40707 through 2022-40709: Out-of-bounds read vulnerabilities in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations.
Affected versions:
Versions 20 of the Trend Micro Deep Security Agent for Windows only.
QID Detection Logic(Authenticated):
This QID checks for vulnerable version of Trend Micro Deep Security Agent by checking the file version
On successful exploitation the attacker may be able to elevate the privileges impacting confidentiality, integrity, and availability.
- 000291590 -
success.trendmicro.com/dcx/s/solution/000291590
CVEs related to QID 378531
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 000291590 |
|