#VU96901 Input validation error in Antivirus One - CVE-2024-45335

 

#VU96901 Input validation error in Antivirus One - CVE-2024-45335

Published: September 5, 2024


Vulnerability identifier: #VU96901
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-45335
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Antivirus One
Software vendor:
Trend Micro

Description

The vulnerability allows an attacker to bypass malware detection.

The vulnerability exists due to insufficient validation of extended file attributes when scanning files. A remote attacker can evade malware detection using specially crafted attributes for the malicious binary file.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Remediation

Install updates from vendor's website.

External links