CVE-2023-52338
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2023-52338 is a newly disclosed privilege escalation vulnerability affecting Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent. The issue arises from a link following vulnerability, enabling local attackers to escalate their privileges on targeted installations. It is important to note that an attacker must initially gain the capability to execute low-privileged code on the victim's system to successfully exploit this vulnerability. By exploiting this weakness, attackers could elevate their access, potentially leading to unauthorized system modifications or data exfiltration. System administrators are advised to apply the available patches promptly to mitigate the risk of potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Trend Micro Deep Security Agent
- Trend Micro Deep Security
Affected Vendors
- Trend Micro, Inc.