Code Injection Vulnerability in Trend Micro Deep Security and Cloud One Product
CVE-2022-23120
7.8HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 20 January 2022
Summary
A code injection vulnerability exists in Trend Micro's Deep Security and Cloud One - Workload Security Agent for Linux, specifically in versions 20 and below. This vulnerability allows an attacker, who has gained access to the target agent while it remains un-activated and unconfigured, to escalate privileges and execute arbitrary code with root privileges. This can lead to significant security risks if not addressed promptly. It is crucial for users to ensure their systems are properly configured and secured.
Affected Version(s)
Trend Micro Deep Security Agent for Linux 20, 12, 11, 10
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved