An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. Please note: an attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
2022-03-08T22:15:07.827
2024-11-21T06:53:44.863
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | trendmicro | portable_security | < 2.0.8056 | Yes |
Application | trendmicro | portable_security | < 3.0.5054 | Yes |
Application | trendmicro | portable_security | < 3.0.5054 | Yes |