VYPR
Unrated severityNVD Advisory· Published Jun 9, 2022· Updated Aug 3, 2024

CVE-2022-30703

CVE-2022-30703

Description

Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attacker to obtain access to leaked kernel addresses and disclose sensitive information. This vulnerability could also potentially be chained for privilege escalation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Trend Micro Security 2021 and 2022 expose a dangerous method in the NCIE Scanner module, allowing local attackers to leak kernel addresses for privilege escalation.

Vulnerability

CVE-2022-30703 is an exposed dangerous method vulnerability in Trend Micro Security 2021 and 2022 consumer products. The flaw resides in the NCIE Scanner module, which exposes a dangerous function to unprivileged users [1]. Affected versions include Trend Micro Security 2022 (17.7.1383 and below) and Trend Micro Security 2021 (17.0.1394 and below) on Microsoft Windows [2].

Exploitation

An attacker must first obtain the ability to execute low-privileged code on the target system [1]. No user interaction beyond the initial code execution is required, as the vulnerable function is directly accessible to unprivileged users [1]. The attack has a local attack vector and requires low privileges [1][2].

Impact

A successful exploit allows the attacker to leak kernel addresses and disclose sensitive information [1][2]. This kernel address disclosure could be chained with other vulnerabilities to achieve privilege escalation or execute arbitrary code in the kernel context [1][2]. The CVSSv3 score is 6.5 (Medium), with high impact on confidentiality [2].

Mitigation

Trend Micro released fixes via ActiveUpdate. Affected users should update Trend Micro Security 2022 to version 17.7.1472 or above, and Trend Micro Security 2021 to version 17.0.1394 or above [2]. The update was released on May 20, 2022 [2]. There are no known workarounds, and no evidence of active exploitation was reported at the time of disclosure [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.