CVE-2018-6234: Trend Micro Maximum Security tmnciesc Out-Of-Bounds Read Information Disclosure Vulnerability
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6234?
The severity of CVE-2018-6234 is medium with a severity value of 5.5.
How does CVE-2018-6234 affect Trend Micro Maximum Security?
CVE-2018-6234 allows local attackers to disclose sensitive information on vulnerable installations of Trend Micro Maximum Security.
How can CVE-2018-6234 be exploited?
To exploit CVE-2018-6234, an attacker must first obtain the ability to execute low-privileged code on the target system.
What is the affected software for CVE-2018-6234?
The affected software for CVE-2018-6234 includes Trend Micro Maximum Security versions up to 12.0 and related products.
Where can I find more information about CVE-2018-6234?
More information about CVE-2018-6234 can be found at the following references: [1], [2].