CVE-2022-24671

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
24/02/2022
Last modified:
03/03/2022

Description

A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modify a file during the update process and escalate their privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:antivirus:*:*:*:*:*:macos:*:* 11.0.2150 (including)