CVE-2024-23940
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system.
Trend Micro uiAirSupport, incluido en la familia de productos de consumo Trend Micro Security 2023, versión 6.0.2092 y anteriores, es vulnerable a una vulnerabilidad de secuestro/proxy de DLL que, si se explota, podría permitir a un atacante hacerse pasar por una librería y modificarla para ejecutar código en el sistema y, en última instancia, escalar privilegios en un sistema afectado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-24 CVE Reserved
- 2024-01-29 CVE Published
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- 2025-02-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://medium.com/@s1kr10s/av-when-a-friend-becomes-an-enemy-55f41aba42b1 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpcenter.trendmicro.com/en-us/article/tmka-12134 | 2024-02-06 | |
https://helpcenter.trendmicro.com/ja-jp/article/tmka-12132 | 2024-02-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Air Support Search vendor "Trendmicro" for product "Air Support" | < 6.0.2103 Search vendor "Trendmicro" for product "Air Support" and version " < 6.0.2103" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Trendmicro Search vendor "Trendmicro" | Antivirus \+ Security Search vendor "Trendmicro" for product "Antivirus \+ Security" | < 6.0.2103 Search vendor "Trendmicro" for product "Antivirus \+ Security" and version " < 6.0.2103" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Trendmicro Search vendor "Trendmicro" | Internet Security Search vendor "Trendmicro" for product "Internet Security" | < 6.0.2103 Search vendor "Trendmicro" for product "Internet Security" and version " < 6.0.2103" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Trendmicro Search vendor "Trendmicro" | Maximum Security Search vendor "Trendmicro" for product "Maximum Security" | < 6.0.2103 Search vendor "Trendmicro" for product "Maximum Security" and version " < 6.0.2103" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Trendmicro Search vendor "Trendmicro" | Premium Security Search vendor "Trendmicro" for product "Premium Security" | < 6.0.2103 Search vendor "Trendmicro" for product "Premium Security" and version " < 6.0.2103" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|