7.5

CVE-2022-24678

An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow an attacker to flood a temporary log location and consume all disk space on affected installations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version - SwEdition saas
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex One Version 2019
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Services Version - SwEdition saas
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.34% 0.817
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://success.trendmicro.com/solution/000290464
Patch
Vendor Advisory
https://success.trendmicro.com/solution/000290486
Patch
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-22-372/
Third Party Advisory
VDB Entry