Description
A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malicious executable to a specific location and in the process of removal and restoral an attacker could replace an original folder with a mount point to an arbitrary location, allowing a escalation of privileges on an affected system.
Published: 2023-01-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-50902 A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malicious executable to a specific location and in the process of removal and restoral an attacker could replace an original folder with a mount point to an arbitrary location, allowing a escalation of privileges on an affected system.
History

Fri, 04 Apr 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Microsoft Windows
Trendmicro Maximum Security 2022
cve-icon MITRE

Status: PUBLISHED

Assigner: trendmicro

Published:

Updated: 2025-04-03T19:53:47.060Z

Reserved: 2022-12-30T02:27:10.986Z

Link: CVE-2022-48191

cve-icon Vulnrichment

Updated: 2024-08-03T15:10:59.793Z

cve-icon NVD

Status : Modified

Published: 2023-01-20T07:15:12.010

Modified: 2025-04-03T20:15:17.747

Link: CVE-2022-48191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses