Description
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-2432 | A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. |
References
History
No history.
Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2024-08-05T07:39:07.401Z
Reserved: 2018-04-24T00:00:00.000Z
Link: CVE-2018-10358
No data.
Status : Modified
Published: 2018-06-08T14:29:00.207
Modified: 2024-11-21T03:41:15.397
Link: CVE-2018-10358
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD