CVE-2023-25144
- EPSS 0.3%
- Veröffentlicht 10.03.2023 21:15:14
- Zuletzt bearbeitet 06.03.2025 16:15:40
An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership.
CVE-2023-0587
- EPSS 59.59%
- Veröffentlicht 01.02.2023 03:15:08
- Zuletzt bearbeitet 27.03.2025 15:15:42
A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload ar...
CVE-2022-45798
- EPSS 0.3%
- Veröffentlicht 24.12.2022 00:15:08
- Zuletzt bearbeitet 15.04.2025 14:15:37
A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a fi...
CVE-2022-44647
- EPSS 0.7%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 29.04.2025 16:15:27
An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-p...
CVE-2022-44648
- EPSS 0.7%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 29.04.2025 05:15:45
An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-p...
CVE-2022-44649
- EPSS 0.35%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 29.04.2025 05:15:45
An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first...
CVE-2022-44650
- EPSS 0.35%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 29.04.2025 05:15:46
A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obt...
- EPSS 0.16%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 28.04.2025 19:15:45
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute ...
CVE-2022-44652
- EPSS 0.35%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 28.04.2025 18:15:45
An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to...
CVE-2022-44653
- EPSS 0.58%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 28.04.2025 18:15:46
A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute l...