An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://success.trendmicro.com/solution/000287819 | vendor advisory |
https://success.trendmicro.com/jp/solution/000287796 | vendor advisory |
https://success.trendmicro.com/solution/000286857 | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-910/ | vdb entry third party advisory |