Vulnerability CVE-2018-3608


Published: 2018-07-06

Description:
A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Trendmicro -> Antivirus + security 
Trendmicro -> Internet security 
Trendmicro -> Maximum security 
Trendmicro -> Officescan 
Trendmicro -> Officescan monthly 
Trendmicro -> Premium security 

 References:
http://esupport.trendmicro.com/support/vb/solution/ja-jp/1120144.aspx
https://esupport.trendmicro.com/en-US/home/pages/technical-support/1120237.aspx

Copyright 2020, cxsecurity.com

 

Back to Top