CVE-2022-35234
Description
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A local out-of-bounds read in Trend Micro Security 2021/2022 allows low-privileged code to disclose sensitive memory and crash the system.
Vulnerability
An out-of-bounds read vulnerability exists in the User Mode Hooking Monitor Engine of Trend Micro Maximum Security, part of the Trend Micro Security 2021 and 2022 consumer product line. The issue stems from a lack of proper validation of user-supplied data, which can result in reading past the end of an allocated buffer. Affected versions include Trend Micro Security 2022 (17.7.1383 and below) [1][2].
Exploitation
To exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system. No additional user interaction is required beyond code execution at a low integrity level. The flaw is reachable locally, and the attacker can trigger the out-of-bounds read by supplying crafted data to the vulnerable engine component [1].
Impact
Successful exploitation allows an attacker to read sensitive information from other memory locations, potentially leaking data such as secrets or credentials. Additionally, the out-of-bounds read can cause a crash of the affected product. An attacker can leverage this vulnerability in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of SYSTEM [1].
Mitigation
Trend Micro has released a fix via ActiveUpdate, updating Trend Micro Security to version 17.7.1634. Users should ensure their product is updated to this version or later. No reports of active exploitation in the wild have been received at the time of disclosure [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: = 2021
- Range: 2022 (17.7.1383 and below)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- helpcenter.trendmicro.com/en-us/article/tmka-11058mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-22-962/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.