Link following in Apex One and Worry-Free Business Security - CVE-2022-36336
Published: July 28, 2022
Apex One
Worry-Free Business Security
Trend Micro
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure link following within the NT Apex One RealTime Scan Service. A local user can create a mount point and delete arbitrary files on the system.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code with SYSTEM privileges.