Vulnerabilities > Trendmicro
|2022-06-09||CVE-2022-30702|| Out-of-bounds Read vulnerability in Trendmicro Security 2022 |
Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that could allow an attacker to disclose sensitive information on an affected machine.
| 2.1 |
|2022-06-09||CVE-2022-30703|| Unspecified vulnerability in Trendmicro Security 2021/2022 |
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attacker to obtain access to leaked kernel addresses and disclose sensitive information.
| 4.6 |
|2022-05-27||CVE-2022-28394|| Uncontrolled Search Path Element vulnerability in Trendmicro Password Manager |
EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 22.214.171.1243 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).
| 6.9 |
|2022-05-27||CVE-2022-30687|| Link Following vulnerability in Trendmicro Maximum Security 2022 17.7 |
Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product's secure erase feature to delete arbitrary files.
| 6.6 |
|2022-05-27||CVE-2022-30700|| Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Apex ONE 2019 |
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations.
| 7.2 |
|2022-05-27||CVE-2022-30701|| Uncontrolled Search Path Element vulnerability in Trendmicro Apex ONE 2019 |
An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to craft a special configuration file to load an untrusted library with escalated privileges on affected installations.
| 7.2 |
|2022-05-16||CVE-2022-30523|| Link Following vulnerability in Trendmicro Password Manager |
Trend Micro Password Manager (Consumer) version 126.96.36.1996 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYSTEM which can then be used for privilege escalation on the affected machine.
| 7.2 |
|2022-04-09||CVE-2022-27883|| Link Following vulnerability in Trendmicro Antivirus for mac |
A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation.
| 8.5 |
|2022-03-29||CVE-2022-26871|| Unrestricted Upload of File with Dangerous Type vulnerability in Trendmicro Apex Central and Apex ONE |
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
| 7.5 |
|2022-03-08||CVE-2022-26319|| Uncontrolled Search Path Element vulnerability in Trendmicro Portable Security 2.0/3.0 |
An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges.
| 6.9 |