CVE-2022-30703
Description
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attacker to obtain access to leaked kernel addresses and disclose sensitive information. This vulnerability could also potentially be chained for privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Trend Micro Security 2021 and 2022 expose a dangerous method in the NCIE Scanner module, allowing local attackers to leak kernel addresses for privilege escalation.
Vulnerability
CVE-2022-30703 is an exposed dangerous method vulnerability in Trend Micro Security 2021 and 2022 consumer products. The flaw resides in the NCIE Scanner module, which exposes a dangerous function to unprivileged users [1]. Affected versions include Trend Micro Security 2022 (17.7.1383 and below) and Trend Micro Security 2021 (17.0.1394 and below) on Microsoft Windows [2].
Exploitation
An attacker must first obtain the ability to execute low-privileged code on the target system [1]. No user interaction beyond the initial code execution is required, as the vulnerable function is directly accessible to unprivileged users [1]. The attack has a local attack vector and requires low privileges [1][2].
Impact
A successful exploit allows the attacker to leak kernel addresses and disclose sensitive information [1][2]. This kernel address disclosure could be chained with other vulnerabilities to achieve privilege escalation or execute arbitrary code in the kernel context [1][2]. The CVSSv3 score is 6.5 (Medium), with high impact on confidentiality [2].
Mitigation
Trend Micro released fixes via ActiveUpdate. Affected users should update Trend Micro Security 2022 to version 17.7.1472 or above, and Trend Micro Security 2021 to version 17.0.1394 or above [2]. The update was released on May 20, 2022 [2]. There are no known workarounds, and no evidence of active exploitation was reported at the time of disclosure [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2022 (17.7.1383 and below)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- helpcenter.trendmicro.com/en-us/article/tmka-11021mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-22-801/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.