CVE-2022-26319
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
08/03/2022
Last modified:
19/03/2022
Description
An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. Please note: an attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:trendmicro:portable_security:*:*:*:*:*:*:*:* | 2.0 (including) | 2.0.8056 (excluding) |
| cpe:2.3:a:trendmicro:portable_security:*:*:*:*:*:*:*:* | 3.0 (including) | 3.0.5054 (excluding) |
| cpe:2.3:a:trendmicro:portable_security:*:*:*:*:pro:*:*:* | 3.0 (including) | 3.0.5054 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



