Link following in Apex One - CVE-2021-45231
Published: December 29, 2021 / Updated: January 6, 2022
Apex One
Trend Micro
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure link following. A local user
can create a specially crafted symbolic link and overwrite arbitrary
files with arbitrary content. Successful exploitation of the vulnerability may result in execution of arbitrary code with elevated privileges.