CVE-2022-28339

Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trendmicro:housecall_for_home_networks:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

29 Jul 2025, 20:41

Type Values Removed Values Added
First Time Microsoft
Microsoft windows
Trendmicro
Trendmicro housecall For Home Networks
Summary
  • (es) Trend Micro HouseCall for Home Networks versión 5.3.1302 y anteriores contiene una vulnerabilidad de elemento de parche de búsqueda no controlada que podría permitir que un atacante con privilegios de usuario bajos cree una DLL maliciosa que podría conducir a privilegios aumentados.
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:housecall_for_home_networks:*:*:*:*:*:*:*:*
References () https://helpcenter.trendmicro.com/en-us/article/tmka-21734 - () https://helpcenter.trendmicro.com/en-us/article/tmka-21734 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-22-620/ - () https://www.zerodayinitiative.com/advisories/ZDI-22-620/ - Third Party Advisory

24 Feb 2025, 13:15

Type Values Removed Values Added
CWE CWE-427

22 Feb 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-22 21:15

Updated : 2025-07-29 20:41


NVD link : CVE-2022-28339

Mitre link : CVE-2022-28339

CVE.ORG link : CVE-2022-28339


JSON object : View

Products Affected

trendmicro

  • housecall_for_home_networks

microsoft

  • windows
CWE
CWE-427

Uncontrolled Search Path Element