CVE-2024-36307
Trend Micro Apex One Security Agent Link Following Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information about the agent on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Un enlace de agente de seguridad tras una vulnerabilidad en Trend Micro Apex One y Apex One as a Service podría permitir a un atacante local revelar información confidencial sobre el agente en las instalaciones afectadas. Tenga en cuenta: un atacante primero debe obtener la capacidad de ejecutar código con pocos privilegios en el sistema de destino para poder explotar esta vulnerabilidad.
This vulnerability allows local attackers to disclose sensitive information on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the VsApiNT module. By creating a mount point, an attacker can abuse the agent to disclose the contents of a file. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-23 CVE Reserved
- 2024-06-06 CVE Published
- 2024-06-11 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://success.trendmicro.com/dcx/s/solution/000298063 | ||
https://www.zerodayinitiative.com/advisories/ZDI-24-573 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trend Micro, Inc. Search vendor "Trend Micro, Inc." | Trend Micro Apex One Search vendor "Trend Micro, Inc." for product "Trend Micro Apex One" | < 14.0.0.12980 Search vendor "Trend Micro, Inc." for product "Trend Micro Apex One" and version " < 14.0.0.12980" | en |
Affected
| ||||||
Trend Micro, Inc. Search vendor "Trend Micro, Inc." | Trend Micro Apex One As A Service Search vendor "Trend Micro, Inc." for product "Trend Micro Apex One As A Service" | >= SaaS < 14.0.13139 Search vendor "Trend Micro, Inc." for product "Trend Micro Apex One As A Service" and version " >= SaaS < 14.0.13139" | en |
Affected
|