ZDI-CAN-6370: Trend Micro Anti-Virus KERedirect Untrusted Pointer Dereference Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Trend Micro Anti-Virus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the KERedirect kext. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the kernel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-6370?
The severity of ZDI-CAN-6370 is significant as it allows local attackers to escalate privileges.
How do I fix ZDI-CAN-6370?
To fix ZDI-CAN-6370, update Trend Micro Anti-Virus to the latest version provided by the vendor.
Who is affected by ZDI-CAN-6370?
ZDI-CAN-6370 affects installations of Trend Micro Anti-Virus that are not updated to the latest security patches.
Can ZDI-CAN-6370 be exploited remotely?
No, ZDI-CAN-6370 requires local access to the system to exploit the privilege escalation flaw.
What are the potential impacts of exploiting ZDI-CAN-6370?
Exploiting ZDI-CAN-6370 could allow an attacker to gain elevated privileges on the affected system.