CVE-2022-28339

CWE-4273 documents3 sources
Severity
7.8HIGH
EPSS
0.1%
top 78.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22

Description

Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-7vcf-jcc6-ppj2: Trend Micro HouseCall for Home Networks version 52025-02-22
CVEList
CVE-2022-28339: Trend Micro HouseCall for Home Networks version 52025-02-22
CVE-2022-28339 (HIGH CVSS 7.8) | Trend Micro HouseCall for Home Netw | cvebase.io