CVE-2022-28339

HIGH

Trend Micro HouseCall <5.3.1302 - Code Injection

Title source: llm
STIX 2.1

Description

Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.

References (2)

Core 2

Scores

CVSS v3 7.3
EPSS 0.0007
EPSS Percentile 21.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-427
Status published
Products (1)
trendmicro/housecall_for_home_networks < 5.3.1308
Published Feb 22, 2025
Tracked Since Feb 18, 2026