First published: Tue Jun 12 2018(Updated: )
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissions on vulnerable installations. An attacker must already have at least guest privileges in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Officescan | =11.0-sp1 | |
Trendmicro Officescan | =xg | |
Trendmicro Officescan | =xg-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10508 is a vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG that allows an attacker to elevate account permissions using a specially crafted URL.
CVE-2018-10508 has a severity score of 8.8, which is considered high.
CVE-2018-10508 affects Trend Micro OfficeScan 11.0 SP1 and XG.
To exploit CVE-2018-10508, an attacker must already have at least guest privileges and use a specially crafted URL.
Yes, Trend Micro has provided a solution for CVE-2018-10508. Please refer to the official documentation for more information.