ZDI-CAN-15757: Trend Micro Internet Security Exposed Dangerous Method Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Trend Micro Internet Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the NCIE Scanner module. The module exposes a dangerous function to unprivileged users. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-15757?
The severity of ZDI-CAN-15757 is classified as a medium risk, given that it allows local attackers to disclose sensitive information.
How do I fix ZDI-CAN-15757?
To fix ZDI-CAN-15757, ensure that you update your Trend Micro Internet Security to the latest version provided by the vendor.
Who is affected by ZDI-CAN-15757?
ZDI-CAN-15757 affects users of Trend Micro Internet Security 2023 on systems that allow local code execution.
How does ZDI-CAN-15757 impact my system?
ZDI-CAN-15757 can allow local attackers to disclose sensitive information on your system, posing a risk to data confidentiality.
What type of attacker exploits ZDI-CAN-15757?
ZDI-CAN-15757 can be exploited by local attackers who have the ability to execute low-privileged code on the target system.