Trend Micro Apex Security Update 28 July 2022

Trend Micro has released the security update for spyware pattern for Trend Micro Apex One that resolves the agent link following local privilege escalation vulnerability related to the scanning function. The remote attacker could exploit this vulnerability to escalate privileges on the system.

The addressed vulnerability could allow the authenticated attacker to gain elevated privileges on the system caused by a link following the vulnerability in the scanning function.


Trend Micro Apex One and Worry-Free Business Security privilege escalation (CVE-2022-36336):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Escalate Privileges
Vulnerabilities

CVE-2022-36336

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.
Trend Micro Apex Security Update

References