Privilege Escalation in Trend Micro VPN Proxy Pro by Trend Micro
CVE-2022-33158

7.8HIGH

Key Information:

Vendor
CVE Published:
30 July 2022

Summary

Trend Micro VPN Proxy Pro versions earlier than 5.2.1026 are vulnerable to a privilege escalation issue due to overly permissive folder permissions within a critical directory. This flaw may enable local attackers to gain elevated privileges, potentially compromising system integrity and security. Organizations using affected versions should prioritize upgrading to secure their infrastructure.

Affected Version(s)

Trend Micro VPN Proxy One Pro (Consumer) 5.2.1026 and below

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.