First published: Tue Jun 12 2018(Updated: )
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh attack on vulnerable installations. An attacker must be using a AD logon user account in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Officescan | =11.0-sp1 | |
Trendmicro Officescan | =xg | |
Trendmicro Officescan | =xg-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10509 is a vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG that could allow an attacker to exploit it via a Browser Refresh attack on vulnerable installations.
CVE-2018-10509 has a severity rating of 8.8 (high).
An attacker can exploit CVE-2018-10509 by using a Browser Refresh attack on vulnerable installations, while logged in with an AD logon user account.
CVE-2018-10509 affects Trend Micro OfficeScan versions 11.0 SP1, XG, and XG SP1.
Yes, a fix is available for CVE-2018-10509. Please refer to the official Trend Micro website for more information.