Trend Micro Security Update 02 January 2023

Trend Micro has released a security update to address a vulnerability affecting Trend Micro Maximum Security version 2022 (v17.7).

The severity of the addressed vulnerability could allow the low-privileged attacker to write a malicious executable to a specific location and in the process of removal and restoral, the attacker could replace an original folder with a mount point to an arbitrary location, allowing escalation of privileges on the affected system.

Trend Micro Maximum Security Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability (CVE-2022-48191):

• CVSS: 7.8

• Attack Vector: Local

• Attack Complexity: Low

• Privileges Required: Low

• User Interaction: None

• Consequences: Privilege Escalation

Vulnerabilities
  • CVE-2022-48191
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Trend Micro Security Bulletin

References