Input validation error in Antivirus One - CVE-2024-45335

 

Input validation error in Antivirus One - CVE-2024-45335

Published: September 5, 2024


Vulnerability identifier: #VU96901
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-45335
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Trend Micro
Affected software:
Antivirus One

Detailed vulnerability description

The vulnerability allows an attacker to bypass malware detection.

The vulnerability exists due to insufficient validation of extended file attributes when scanning files. A remote attacker can evade malware detection using specially crafted attributes for the malicious binary file.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


How to mitigate CVE-2024-45335

Install updates from vendor's website.

Sources