Local Privilege Escalation in Trend Micro HouseCall
CVE-2022-38764
7.8HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 19 September 2022
Summary
A vulnerability in Trend Micro HouseCall versions up to 1.62.1.1133 allows local attackers to escalate privileges. This is due to an overly permissive folder in the product installer, which can be exploited to gain unauthorized access and control over the system. Implementing proper permission settings is crucial to mitigate this risk.
Affected Version(s)
Trend Micro HouseCall (Consumer) 1.62.1.1133
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved