CVE-2018-6235: Trend Micro Maximum Security tmnciesc Out-Of-Bounds Write Privilege Escalation Vulnerability
An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2018-6235.
What software is affected by this vulnerability?
Trend Micro Maximum Security versions up to and including 12.0 are affected by this vulnerability.
How do attackers exploit this vulnerability?
Attackers must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
What is the severity of CVE-2018-6235?
The severity of CVE-2018-6235 is high, with a CVSS score of 7.8.
How can I fix this vulnerability?
You can fix this vulnerability by updating your installation of Trend Micro Maximum Security to the latest version available.