Release Date: May 13, 2022
CVE Vulnerability Identifier: CVE-2022-30687
Platform(s): Windows OS
CVSSv3 Score: 6.1
Severity Rating: Medium
Summary
Trend Micro has released an update via ActiveUpdate for Trend Micro Maximum Security 2022 which resolves a link following arbitrary file deletion vulnerability.
Affected version(s)
PRODUCT | AFFECTED VERSION(S) | PLATFORM | LANGUAGE(S) |
---|---|---|---|
Trend Micro Maximum Security | 2022 (v17.7) | Windows | English |
Solution
Trend Micro has released an update via ActiveUpdate that resolves the issue.
PRODUCT | UPDATED VERSION(S) | PLATFORM | LANGUAGE(S) |
---|---|---|---|
Trend Micro Maximum Security | 17.7.1634 | Windows | English |
Vulnerability Details
Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product’s secure erase feature to delete arbitrary files.
Trend Micro has received no reports nor is aware of any actual attacks against the affected products related to this vulnerability at this time.
Mitigating Factors
None identified. Customers are advised to ensure they always have the latest version of the program.
Acknowledgement
Trend Micro would like to thank the following individual for responsibly disclosing the issue and working with Trend Micro to help protect our customers:
- Amir Ahmadi (@KingAmir ) working with Trend Micro Zero Day Initiative
Additional Assistance
Customers who have questions are encouraged to contact Trend Micro Technical Support for further assistance.
External Reference
The following advisories may be found at Trend Micro's Zero Day Initiative Published Advisories site:
- ZDI-CAN-15739