Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://helpcenter.trendmicro.com/en-us/article/tmka-21734 | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-22-620/ | third party advisory |