Local Privilege Escalation in Trend Micro HouseCall
CVE-2022-38764

7.8HIGH

Key Information:

Vendor
CVE Published:
19 September 2022

Summary

A vulnerability in Trend Micro HouseCall versions up to 1.62.1.1133 allows local attackers to escalate privileges. This is due to an overly permissive folder in the product installer, which can be exploited to gain unauthorized access and control over the system. Implementing proper permission settings is crucial to mitigate this risk.

Affected Version(s)

Trend Micro HouseCall (Consumer) 1.62.1.1133

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.