Link following in Apex One and Worry-Free Business Security - CVE-2022-36336

 

Link following in Apex One and Worry-Free Business Security - CVE-2022-36336

Published: July 28, 2022


Vulnerability identifier: #VU65870
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-36336
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Apex One
Worry-Free Business Security
Software vendor:
Trend Micro

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insecure link following within the NT Apex One RealTime Scan Service. A local user can create a mount point and delete arbitrary files on the system.

Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code with SYSTEM privileges.


Remediation

The resolution for this issue is deployed automatically via ActiveUpdate to customers in an updated Spyware pattern 25.27.

External links