CVE-2022-44647
Description
An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
This is similar to, but not the same as CVE-2022-44648.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Out-of-bounds read in Trend Micro Apex One allows local attackers to disclose sensitive information and potentially escalate privileges.
Vulnerability
This vulnerability is an out-of-bounds read issue in the User Mode Hooking Monitor Engine of Trend Micro Apex One and Apex One as a Service. The lack of proper validation of user-supplied data can result in a read past the end of an allocated buffer. The specific affected versions are not explicitly listed in the available references, but the flaw affects installations of Trend Micro Apex One Security Agent [1].
Exploitation
An attacker must first obtain the ability to execute low-privileged code on the target system. By supplying specially crafted data to the User Mode Hooking Monitor Engine, the attacker can trigger an out-of-bounds read. This can be leveraged to disclose sensitive information from memory. Additionally, this vulnerability can be used in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code with SYSTEM privileges [1].
Impact
Successful exploitation allows a local attacker to disclose sensitive information. When combined with other vulnerabilities, it can lead to privilege escalation to SYSTEM and arbitrary code execution. The CVSS score is 4.4, indicating a moderate severity [1].
Mitigation
Trend Micro has released security updates to address this vulnerability. Users are advised to apply the latest patches as described in the vendor advisory. No workarounds have been provided in the available references [2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Trend Micro, Inc./Trend Micro Apex Onev5Range: On Premise (14.0)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.