ZDI-18-1297: Trend Micro Anti-Virus KERedirect Untrusted Pointer Dereference Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Trend Micro Anti-Virus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the KERedirect kext. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the kernel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-18-1297?
The severity of ZDI-18-1297 is critical as it allows local attackers to escalate privileges on Trend Micro Anti-Virus installations.
How do I fix ZDI-18-1297?
To fix ZDI-18-1297, ensure you apply the latest security updates provided by Trend Micro for their Anti-Virus software.
Who is affected by ZDI-18-1297?
ZDI-18-1297 affects users of vulnerable installations of Trend Micro Anti-Virus software.
What type of attack does ZDI-18-1297 enable?
ZDI-18-1297 enables local attackers to escalate their privileges after executing low-privileged code on the target system.
Is there a workaround for ZDI-18-1297?
There is no known workaround for ZDI-18-1297, and it is strongly recommended to apply the latest updates from Trend Micro.