Lucene search

K
cveTrendmicroCVE-2018-15367
HistoryOct 23, 2018 - 2:29 p.m.

CVE-2018-15367

2018-10-2314:29:01
CWE-476
trendmicro
web.nvd.nist.gov
19
cve-2018-15367
privilege escalation
trend micro
antivirus
mac
vulnerability
privilege escalation vulnerability
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.9%

A ctl_set KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Affected configurations

Nvd
Node
trendmicroantivirus_for_mac_2017Range7.07.1.1124
OR
trendmicroantivirus_for_mac_2018Range8.08.0.3082
OR
trendmicroantivirus_for_mac_2019Range9.09.0.1356
VendorProductVersionCPE
trendmicroantivirus_for_mac_2017*cpe:2.3:a:trendmicro:antivirus_for_mac_2017:*:*:*:*:*:*:*:*
trendmicroantivirus_for_mac_2018*cpe:2.3:a:trendmicro:antivirus_for_mac_2018:*:*:*:*:*:*:*:*
trendmicroantivirus_for_mac_2019*cpe:2.3:a:trendmicro:antivirus_for_mac_2019:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Trend Micro Antivirus for Mac (Consumer)",
    "vendor": "Trend Micro",
    "versions": [
      {
        "status": "affected",
        "version": "7.0 (2017) and above"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.9%

Related for CVE-2018-15367