Versio.io

CVE-2022-27883

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 09-04-2022 02:15
Last modified: - 14-04-2022 09:34
Total changes: - 3

Description

A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to exploit this vulnerability.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Low
Attack complexity
Local
Attack vector
High
Availability
High
Confidentiality
High
Integrity
Low
Privileges required
Unchanged
Scope
Required
User interaction
7.3
Base score
1.3
5.9
Exploitability score
Impact score
 

Verification logic

OR
vendor=trendmicro AND product=antivirus_for_mac AND versionEndIncluding=11.5
 

Reference

  • N/A-Third Party Advisory, VDB Entry
  • N/A-Vendor Advisory
 


Keywords

NVD

 

CVE-2022-27883

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.