RSS   Vulnerabilities for 'Antivirus+'   RSS

2018-05-25
 
CVE-2018-6236

CWE-362
 

 
A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222813 by the tmusa driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

 
 
CVE-2018-6235

CWE-787
 

 
An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

 
 
CVE-2018-6234

CWE-200
 

 
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

 
 
CVE-2018-6233

CWE-264
 

 
A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222060 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

 
 
CVE-2018-6232

CWE-264
 

 
A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x22205C by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

 
2017-03-21
 
CVE-2017-5565

 

 
Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Trend Micro process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.

 

 >>> Vendor: Trendmicro 31 Products
Internet security
Officescan
Trend micro internet security
Housecall
Trend micro antivirus
Internet security 2010
Interscan messaging security suite
Interscan messaging security virtual appliance
Interscan web security virtual appliance
Tmeext.sys
Maximum security
Premium security
Antivirus+
Mobile security
Threat discovery appliance
Serverprotect
Deep discovery director
Control manager
Deep discovery email inspector
Trend micro control manager
Smart protection server
Web security virtual appliance
Officescan xg
Scanmail
Encryption for email
Email encryption gateway
Endpoint application control
Antivirus + security
Officescan monthly
Interscan web security suite
Deep discovery inspector


Copyright 2018, cxsecurity.com

 

Back to Top