CVE-2024-36473
Trend Micro VPN Proxy One Pro Link Following Denial-of-Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local Denial of Service (DoS) and under specific conditions can lead to elevation of privileges.
Trend Micro VPN Proxy One Pro, versión 5.8.1012 y anteriores es vulnerable a un ataque de creación o sobrescritura de archivos arbitrario, pero está limitado a la denegación de servicio (DoS) local y, en condiciones específicas, puede provocar una elevación de privilegios.
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro VPN Proxy One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Vpn Background Controller. By creating a symbolic link, an attacker can abuse the application to create a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-28 CVE Reserved
- 2024-06-10 CVE Published
- 2024-06-12 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://helpcenter.trendmicro.com/en-us/article/tmka-07247 | ||
https://www.zerodayinitiative.com/advisories/ZDI-24-585 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trend Micro, Inc. Search vendor "Trend Micro, Inc." | Trend Micro VPN Proxy One Pro Search vendor "Trend Micro, Inc." for product "Trend Micro VPN Proxy One Pro" | >= 5.8.0 < 5.8.1012 Search vendor "Trend Micro, Inc." for product "Trend Micro VPN Proxy One Pro" and version " >= 5.8.0 < 5.8.1012" | en |
Affected
|