ZDI-20-1226: Trend Micro OfficeScan Hard Link Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro OfficeScan. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the OfficeScan Security Agent. By creating a hard link, an attacker can abuse the service to overwrite the contents of a chosen file. An attacker can leverage this vulnerability to escalate privileges and execute code as an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-20-1226?
The severity of ZDI-20-1226 is categorized as a high-risk vulnerability due to the ability to escalate privileges.
How do I fix ZDI-20-1226?
To fix ZDI-20-1226, ensure that your Trend Micro OfficeScan installation is updated to the latest patched version.
Who is affected by ZDI-20-1226?
ZDI-20-1226 affects installations of Trend Micro OfficeScan XG that have not been updated.
What type of attack is possible with ZDI-20-1226?
ZDI-20-1226 allows local attackers to escalate privileges, gaining higher access on the target system.
What conditions are necessary to exploit ZDI-20-1226?
An attacker must first have the ability to execute low-privileged code on the target system to exploit ZDI-20-1226.