CVE-2004-2430: High severity Trend Micro OfficeScan vulnerability
Trend OfficeScan Corporate Edition 5.58 and possibly earler does not drop privileges when opening a help window from a virus detection pop-up window, which allows local users to gain SYSTEM privileges.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2430?
CVE-2004-2430 is classified as a critical vulnerability due to its potential to allow local users to gain SYSTEM privileges.
How do I fix CVE-2004-2430?
To fix CVE-2004-2430, users should upgrade to a patched version of Trend OfficeScan Enterprise Edition that addresses this privilege escalation issue.
What is the impact of CVE-2004-2430 on affected systems?
The impact of CVE-2004-2430 is that local users on affected systems can elevate their privileges to SYSTEM level, compromising system security.
Which versions of Trend OfficeScan are affected by CVE-2004-2430?
CVE-2004-2430 affects multiple versions of Trend OfficeScan, including corporate editions 3.0, 3.11, 3.5, 3.54, 5.02, 5.5, and 5.58.
Is CVE-2004-2430 a local or remote vulnerability?
CVE-2004-2430 is a local vulnerability, as it requires local access to the system for exploitation.