CVE-2024-23940

CWE-4273 documents3 sources
Severity
7.8HIGH
EPSS
0.1%
top 80.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29

Description

Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

🔴Vulnerability Details

2
CVEList
CVE-2024-23940: Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 62024-01-29
GHSA
GHSA-9fpx-vc83-vhpf: Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 62024-01-29
CVE-2024-23940 (HIGH CVSS 7.8) | Trend Micro uiAirSupport | cvebase.io