NA

CVE-2022-45797

Published: 12/12/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local malicious user to escalate privileges and delete files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

trendmicro apex_one -

trendmicro apex_one 2019

Github Repositories

Aikido Wiper Presented in Black Hat Europe 2022 Briefings under the title - Aikido: Turning EDRs to Malicious Wipers Using 0-day Exploits Full research process is described here - wwwsafebreachcom/resources/blog/safebreach-labs-researcher-discovers-multiple-zero-day-vulnerabilities/ CVEs issued so far Windows Defender & Windows Defender for Endpoint - CVE-202