CVE-2022-26319

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
08/03/2022
Last modified:
19/03/2022

Description

An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. Please note: an attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:portable_security:*:*:*:*:*:*:*:* 2.0 (including) 2.0.8056 (excluding)
cpe:2.3:a:trendmicro:portable_security:*:*:*:*:*:*:*:* 3.0 (including) 3.0.5054 (excluding)
cpe:2.3:a:trendmicro:portable_security:*:*:*:*:pro:*:*:* 3.0 (including) 3.0.5054 (excluding)


References to Advisories, Solutions, and Tools