Remote Authentication Bypass in Trend Micro Mobile Security Enterprise
CVE-2023-32524

8.8HIGH

Key Information:

Vendor
CVE Published:
26 June 2023

Summary

Trend Micro Mobile Security (Enterprise) version 9.8 SP5 contains certain widgets that can be exploited by a remote attacker to bypass authentication controls. This vulnerability requires an attacker to first gain access to execute low-privileged code within the targeted system, allowing this bypass to potentially be chained with other vulnerabilities for greater impact. The nature of this vulnerability emphasizes the importance of strengthening security measures and applying updates to protect against such exploit attempts.

Affected Version(s)

Trend Micro Moibile Security for Enterprise 9.8 SP5 < 9.8.3294

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.