VYPR
Unrated severityNVD Advisory· Published Sep 19, 2022· Updated Aug 3, 2024

CVE-2022-34893

CVE-2022-34893

Description

Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could manipulate a mountpoint which could lead to escalation of privilege on an affected machine.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Trend Micro Security 2022 contains a link following vulnerability allowing local privilege escalation to SYSTEM via a symbolic link.

Vulnerability

A link following vulnerability exists in Trend Micro Security 2022 (consumer) version 17.7.1179 and below [2]. The flaw resides within the Trend Micro Anti-Malware Solution Platform [1]. By creating a symbolic link, an attacker can abuse the service to delete a file [1]. The vulnerability requires the ability to execute low-privileged code on the target system [1].

Exploitation

An attacker must first obtain the ability to execute low-privileged code on the target system [1]. The attacker then creates a symbolic link [1] and manipulates a mountpoint [2] to trigger the link following behavior. The specific steps involve abusing a service within the Trend Micro Anti-Malware Solution Platform to delete a file via the crafted link [1]. No user interaction beyond initial code execution is required. The attack vector is local with low attack complexity [1].

Impact

Successful exploitation allows an attacker to escalate privileges and execute arbitrary code in the context of SYSTEM [1]. The vulnerability leads to complete compromise of confidentiality, integrity, and availability of the affected system [1]. No known actual attacks have been reported against the affected products [2].

Mitigation

Trend Micro has released an update via ActiveUpdate to version 17.7.1634 for Microsoft Windows which resolves the issue [2]. Affected users should ensure they always have the latest version of the program [2]. No workarounds are identified [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.