CVE-2022-37348
Description
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine. This vulnerability is similar to, but not the same as CVE-2022-37347.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Trend Micro Security 2021/2022 contains an out-of-bounds read in the User Mode Hooking Monitor Engine that leaks memory and causes crashes.
Vulnerability
Trend Micro Security 2021 and 2022 (Consumer) versions 17.7.1383 and below are vulnerable to an out-of-bounds read information disclosure vulnerability within the User Mode Hooking Monitor Engine [1][2]. The issue arises from insufficient validation of user-supplied data, allowing a read past the end of an allocated buffer [1]. This vulnerability is distinct from CVE-2022-37347 but shares similar characteristics.
Exploitation
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability [1]. No user interaction beyond executing the low-privileged code is required; the flaw can be triggered from the local context without additional privileges [1][2]. The sequence involves supplying crafted data to the affected engine, resulting in a memory read beyond the intended buffer boundary.
Impact
Successful exploitation allows the attacker to read sensitive information from other memory locations and can cause a crash of the affected application [2]. The CVSSv3 score of 4.4 (AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L) reflects limited confidentiality and availability impact [1][2]. An attacker could leverage this information disclosure in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of SYSTEM [1].
Mitigation
Trend Micro has released an update via ActiveUpdate to version 17.7.1634 to resolve the issue [2]. The fix was included in releases starting July 08, 2022 [2]. No workarounds are necessary; users should ensure their product is updated via the built-in update mechanism. Trend Micro reports no active exploitation at the time of disclosure [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2022 (17.7.1383 and below)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- helpcenter.trendmicro.com/en-us/article/tmka-11058mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-22-1177/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.