A out-of-bounds read information disclosure vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within the processing of IOCTL 0x220004 by the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
2018-06-08T14:29:00.363
2024-11-21T03:41:27.543
Modified
CVSSv3.0: 4.7 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | trendmicro | officescan | 11.0 | Yes |
Application | trendmicro | officescan | xg | Yes |
Application | trendmicro | officescan | xg | Yes |