CVE-2022-26319
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. Please note: an attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
Una vulnerabilidad del elemento de parche de búsqueda del instalador en Trend Micro Portable Security versiones 3.0 Pro, 3.0 y 2.0 podría permitir a un atacante local colocar un archivo DLL generado arbitrariamente en una carpeta del instalador para elevar los privilegios locales. Nota: un atacante debe obtener primero la capacidad de ejecutar código con privilegios elevados en el sistema de destino para poder explotar esta vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-28 CVE Reserved
- 2022-03-08 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://success.trendmicro.com/solution/000290531 | 2022-03-19 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Portable Security Search vendor "Trendmicro" for product "Portable Security" | >= 2.0 < 2.0.8056 Search vendor "Trendmicro" for product "Portable Security" and version " >= 2.0 < 2.0.8056" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Portable Security Search vendor "Trendmicro" for product "Portable Security" | >= 3.0 < 3.0.5054 Search vendor "Trendmicro" for product "Portable Security" and version " >= 3.0 < 3.0.5054" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Portable Security Search vendor "Trendmicro" for product "Portable Security" | >= 3.0 < 3.0.5054 Search vendor "Trendmicro" for product "Portable Security" and version " >= 3.0 < 3.0.5054" | pro |
Affected
|