Views:

Release Date: April 27, 2023

CVE Vulnerability Identifier: CVE-2023-30902

Platform(s): Microsoft Windows

CVSSv3 Scores: 2.9: AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity Rating: Low

Summary

Trend Micro has released an update via ActiveUpdate for the Trend Micro Security for Windows family of consumer products which resolves a Privilege Escalation vulnerability by updating the libraries in version 17.7 of the software.

Affected version(s)

PRODUCTAFFECTED VERSION(S)PLATFORMLANGUAGE(S)
Trend Micro Security 17.7 Microsoft Windows English

Solution

Trend Micro has released an update via ActiveUpdate that resolves the issue.

PRODUCTUPDATED VERSION(S)PLATFORMLANGUAGE(S)
Trend Micro Security 17.7 or higher Microsoft Windows English

Vulnerability Details

Trend Micro Security 17.7 (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys.

Trend Micro has received no reports nor is aware of any actual attacks against the affected product related to this vulnerability at this time.

Acknowledgement

Trend Micro would like to thank the following individual for responsibly disclosing the issue and working with Trend Micro to help protect our customers:

  • Bahaa Naamneh of Crosspoint Labs

Additional Assistance

Customers who have questions are encouraged to contact Trend Micro Technical Support for further assistance.

Add a comment