A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been deployed automatically via ActiveUpdate to customers in an updated Spyware pattern. Customers who are up-to-date on detection patterns are not required to take any additional steps to mitigate this issue.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Apex_one | Trendmicro | - (including) | - (including) |
Apex_one | Trendmicro | 2019 (including) | 2019 (including) |
Worry-free_business_security | Trendmicro | 10.0-sp1 (including) | 10.0-sp1 (including) |
Worry-free_business_security_services | Trendmicro | - (including) | - (including) |