First published: Thu Oct 05 2017(Updated: )
Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan Corporate Edition | =11.0-sp1 | |
Trend Micro OfficeScan | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14088 has been classified as a high-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2017-14088, apply the latest security patches provided by Trend Micro for OfficeScan 11.0 and XG.
CVE-2017-14088 affects Trend Micro OfficeScan version 11.0 SP1 and OfficeScan XG version 12.0.
CVE-2017-14088 enables local attackers to execute arbitrary code and escalate privileges.
CVE-2017-14088 is exploited via the tmwfp.sys component in vulnerable Trend Micro installations.