Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-25147

Опубликовано: 10 мар. 2023
Источник: nvd
CVSS3: 6.7
EPSS Низкий

Описание

An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process.

Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:*:*:*
Версия до 14.0.11960 (исключая)
cpe:2.3:a:trendmicro:apex_one:2019:-:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 2%
0.00013
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427
CWE-427

Связанные уязвимости

CVSS3: 6.7
github
почти 3 года назад

An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.

EPSS

Процентиль: 2%
0.00013
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427
CWE-427