A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220078 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
2018-06-08T14:29:00.270
2024-11-21T03:41:15.520
Modified
CVSSv3.0: 6.3 (MEDIUM)
AV:L/AC:M/Au:N/C:N/I:P/A:C
3.4
7.8
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | trendmicro | officescan | 11.0 | Yes |
Application | trendmicro | officescan | xg | Yes |
Application | trendmicro | officescan | xg | Yes |