Privilege Escalation Vulnerability in Trend Micro HouseCall for Home Networks
CVE-2021-32466

7HIGH

Key Information:

Vendor
CVE Published:
29 September 2021

Summary

An uncontrolled search path element vulnerability in Trend Micro HouseCall for Home Networks allows attackers to escalate privileges. By placing a specially crafted file in a designated directory, a malicious library can be loaded, enabling unauthorized access or control. Attackers must have a foothold to execute low-privileged code on the system in order to exploit this vulnerability. Users of versions 5.3.1225 and earlier should apply patches to mitigate this risk.

Affected Version(s)

Trend Micro HouseCall for Home Networks 5.3.1225 and below

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.