CVE-2014-9641: High severity trendmicro Tmeext.sys vulnerability
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222400 IOCTL call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9641?
CVE-2014-9641 is considered a high-severity vulnerability due to its potential for privilege escalation by allowing local users to write to arbitrary memory locations.
How do I fix CVE-2014-9641?
To fix CVE-2014-9641, users should update the Trend Micro Antivirus Plus, Internet Security, or Maximum Security software to version 2.0.0.1015 or later.
Who is affected by CVE-2014-9641?
CVE-2014-9641 affects users of Trend Micro Antivirus Plus, Internet Security, and Maximum Security versions prior to 2.0.0.1015.
What types of attacks can exploit CVE-2014-9641?
CVE-2014-9641 can be exploited by local attackers to gain elevated privileges through crafted IOCTL calls.
What systems are impacted by CVE-2014-9641?
CVE-2014-9641 impacts systems running vulnerable versions of the tmeext.sys driver within Trend Micro security products.