An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://success.trendmicro.com/solution/000292209 | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-23-171/ | third party advisory vdb entry |