First published: Fri May 25 2018(Updated: )
A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222813 by the tmusa driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Maximum Security | ||
Trend Micro Maximum Security | <=12.0 | |
Trendmicro Internet Security | <=12.0 | |
Trendmicro Maximum Security | <=12.0 | |
Trendmicro Premium Security | <=12.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6236 is a vulnerability found in Trend Micro Maximum Security, which allows local attackers to escalate privileges.
CVE-2018-6236 has a severity value of 7, indicating a high severity.
The affected software includes Trend Micro Maximum Security versions up to and including 12.0.
The vulnerability can be exploited by first gaining the ability to execute low-privileged code on the target system.
You can find more information about CVE-2018-6236 on the official Trend Micro support page and the Zero Day Initiative advisory page.