7.8
CVE-2024-41183
- EPSS 1.01%
- Veröffentlicht 22.10.2024 19:15:05
- Zuletzt bearbeitet 31.07.2025 16:14:21
- Erkennungen
Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that can lead to elevation of privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Vpn SwPlatform windows Version < 5.8.1030
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.01% | 0.597 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Trendmicro | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
https://helpcenter.trendmicro.com/en-us/article/tmka-14460
https://www.zerodayinitiative.com/advisories/ZDI-24-1022/
https://www.zerodayinitiative.com/advisories/ZDI-24-1023/