Privilege Escalation in Trend Micro VPN Proxy Pro by Trend Micro
CVE-2022-33158
7.8HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 30 July 2022
Summary
Trend Micro VPN Proxy Pro versions earlier than 5.2.1026 are vulnerable to a privilege escalation issue due to overly permissive folder permissions within a critical directory. This flaw may enable local attackers to gain elevated privileges, potentially compromising system integrity and security. Organizations using affected versions should prioritize upgrading to secure their infrastructure.
Affected Version(s)
Trend Micro VPN Proxy One Pro (Consumer) 5.2.1026 and below
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved