An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take control of a specific log file on affected installations.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://success.trendmicro.com/solution/000286019 | vendor advisory |
https://success.trendmicro.com/solution/000286157 | vendor advisory |