CVE-2022-34893
Description
Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could manipulate a mountpoint which could lead to escalation of privilege on an affected machine.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Trend Micro Security 2022 contains a link following vulnerability allowing local privilege escalation to SYSTEM via a symbolic link.
Vulnerability
A link following vulnerability exists in Trend Micro Security 2022 (consumer) version 17.7.1179 and below [2]. The flaw resides within the Trend Micro Anti-Malware Solution Platform [1]. By creating a symbolic link, an attacker can abuse the service to delete a file [1]. The vulnerability requires the ability to execute low-privileged code on the target system [1].
Exploitation
An attacker must first obtain the ability to execute low-privileged code on the target system [1]. The attacker then creates a symbolic link [1] and manipulates a mountpoint [2] to trigger the link following behavior. The specific steps involve abusing a service within the Trend Micro Anti-Malware Solution Platform to delete a file via the crafted link [1]. No user interaction beyond initial code execution is required. The attack vector is local with low attack complexity [1].
Impact
Successful exploitation allows an attacker to escalate privileges and execute arbitrary code in the context of SYSTEM [1]. The vulnerability leads to complete compromise of confidentiality, integrity, and availability of the affected system [1]. No known actual attacks have been reported against the affected products [2].
Mitigation
Trend Micro has released an update via ActiveUpdate to version 17.7.1634 for Microsoft Windows which resolves the issue [2]. Affected users should ensure they always have the latest version of the program [2]. No workarounds are identified [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2022 (17.7.1179 and below)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- helpcenter.trendmicro.com/en-us/article/tmka-11053mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-22-1175/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.