CVE-2022-45797Micro INC Trend Micro Apex ONE vulnerability

3 documents3 sources
Severity
7.1HIGHNVD
EPSS
0.1%
top 69.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5trend_micro_inc/trend_micro_apex_oneOn Premise (14.0)14.0.0.11136+1

🔴Vulnerability Details

2
GHSA
GHSA-6wwx-mc3p-m6jg: An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could al2022-12-12
CVEList
CVE-2022-45797: An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could al2022-12-01
CVE-2022-45797 — HIGH severity | cvebase