SB20240905105 - Malware detection bypass in Trend Micro Antivirus One
Published: September 5, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2024-45335)
The vulnerability allows an attacker to bypass malware detection.
The vulnerability exists due to insufficient validation of extended file attributes when scanning files. A remote attacker can evade malware detection using specially crafted attributes for the malicious binary file.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
Remediation
Install update from vendor's website.