Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.
The product, when opening a file or directory, does not sufficiently handle when the file is a Windows shortcut (.LNK) whose target is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
Link | Tags |
---|---|
https://helpcenter.trendmicro.com/en-us/article/tmka-18876 | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-25-585/ | third party advisory |