CVE-2023-32524

Severity
8.8HIGH
EPSS
0.2%
top 59.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateJun 27

Description

Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This is similar to, but not identical to CVE-2023-32523.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7cjr-22fr-r5vf: Affected versions of Trend Micro Mobile Security (Enterprise) 92023-06-27
CVEList
CVE-2023-32524: Affected versions of Trend Micro Mobile Security (Enterprise) 92023-06-26
CVE-2023-32524 (HIGH CVSS 8.8) | Affected versions of Trend Micro Mo | cvebase.io