Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
This is a similar, but not identical vulnerability as CVE-2023-34147 and CVE-2023-34148.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38248 | An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is a similar, but not identical vulnerability as CVE-2023-34147 and CVE-2023-34148. |
Wed, 04 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trend Micro Inc
Trend Micro Inc trend Micro Apex One |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:trend_micro_inc:trend_micro_apex_one:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Trend Micro Inc
Trend Micro Inc trend Micro Apex One |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2024-12-04T16:08:55.833Z
Reserved: 2023-05-26T18:41:36.333Z
Link: CVE-2023-34146
Updated: 2024-08-02T16:01:53.711Z
Status : Modified
Published: 2023-06-26T22:15:11.187
Modified: 2024-12-04T17:15:10.177
Link: CVE-2023-34146
No data.
OpenCVE Enrichment
No data.
EUVD