CVE-2022-45797 is an arbitrary file deletion vulnerability in the Damage Cleanup Engine of Trend Micro Apex One and Apex One as a Service, affecting installations on Microsoft Windows. This flaw allows a local, low-privileged attacker to escalate privileges and delete files. While not actively exploited (KEV: No) and lacking public exploit code (Metasploit, Nuclei, ExploitDB: None), it carries a CVSS score of 7.1 (High) due to its potential for high integrity and availability impact (I:H/A:H) with low attack complexity (AC:L) and no user interaction required (UI:N). The vulnerability has garnered significant community discussion and media coverage, highlighting its potential to turn security products into "wipers."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:-:*:*:*:saas:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.