VYPR
Unrated severityNVD Advisory· Published Jun 9, 2022· Updated Aug 3, 2024

CVE-2022-30702

CVE-2022-30702

Description

Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that could allow an attacker to disclose sensitive information on an affected machine.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local out-of-bounds read in Trend Micro Security 2022 and 2021 allows an authenticated, low-privileged attacker to leak sensitive memory, potentially aiding privilege escalation to SYSTEM.

Vulnerability

The vulnerability exists in the NCIE Scanner module of Trend Micro Security 2022 (version 17.7.1130 and below) and Trend Micro Security 2021 (version 17.0.1394 and below) for Windows [1][2]. The issue is an out-of-bounds read: the software reads beyond the end of an allocated buffer due to improper validation of user-supplied data [1].

Exploitation

An attacker must first be able to execute low-privileged code on the target system [1]. No additional authentication or network access is required beyond local code execution. The flaw is triggered by providing crafted input to the NCIE Scanner module, causing a read past the end of a buffer [1].

Impact

Successful exploitation results in the disclosure of sensitive information from heap memory [1]. The CVSS scope is changed (C), indicating the vulnerability can impact resources beyond the original privilege boundary [2]. An attacker could combine this information disclosure with other vulnerabilities to escalate privileges to SYSTEM and achieve arbitrary code execution [1].

Mitigation

Trend Micro has released updated versions: Security 2022 (v17.7.1472 and above) and Security 2021 (v17.0.1394 and above), distributed automatically via ActiveUpdate [2]. The vendor states no active exploitation has been reported as of the advisory publication [2]. No workaround other than applying the update is available.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.