Page 2 of 12 results (0.010 seconds)

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges. Existe una vulnerabilidad de secuestro de DLL en el componente Folder Shield de la familia de productos de consumo de Trend Micro Security 2019 (v15) y la herramienta independiente Trend Micro Ransom Buster (1.0) en la que, si se explota, permitiría a un atacante cargar una DLL maliciosa, lo que llevaría a Privilegios elevados. • https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123421.aspx • CWE-427: Uncontrolled Search Path Element •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service. Existe una vulnerabilidad de escalada de privilegios locales en Trend Micro Security 2019 (v15.0) en la que, si se explota, permitiría a un atacante manipular una característica específica del producto para cargar un servicio malicioso. • http://packetstormsecurity.com/files/154200/Trend-Maximum-Security-2019-Unquoted-Search-Path.html http://seclists.org/fulldisclosure/2019/Aug/26 https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123420.aspx https://medium.com/sidechannel-br/vulnerabilidade-no-trend-micro-maximum-security-2019-permite-a-escala%C3%A7%C3%A3o-de-privil%C3%A9gios-no-windows-471403d53b68 • CWE-428: Unquoted Search Path or Element •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

A ctl_set KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Una vulnerabilidad de desreferencia de puntero no fiable y escalado de privilegios en ctl_set KERedirect en Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) podría permitir que un atacante local escale privilegios en instalaciones vulnerables. En primer lugar, un atacante debe obtener la capacidad de ejecutar código de bajos privilegios en el sistema objetivo para explotar esta vulnerabilidad. This vulnerability allows local attackers to escalate privileges on vulnerable installations of Trend Micro Anti-Virus. • http://www.securityfocus.com/bid/105757 https://esupport.trendmicro.com/en-US/home/pages/technical-support/1121296.aspx https://esupport.trendmicro.com/solution/ja-jp/1121350.aspx https://www.zerodayinitiative.com/advisories/ZDI-18-1294 • CWE-476: NULL Pointer Dereference •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6F4E offset user-supplied buffer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Una vulnerabilidad de desreferencia de puntero no fiable y escalado de privilegios en KERedirect en Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) podría permitir que un atacante local escale privilegios en instalaciones vulnerables. El problema resulta de la falta de una función de validación adecuada en el búfer de desplazamiento 0x6F4E proporcionado por el usuario. • http://www.securityfocus.com/bid/105757 https://esupport.trendmicro.com/en-US/home/pages/technical-support/1121296.aspx https://esupport.trendmicro.com/solution/ja-jp/1121350.aspx https://www.zerodayinitiative.com/advisories/ZDI-18-1297 • CWE-476: NULL Pointer Dereference •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6eDC offset user-supplied buffer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Una vulnerabilidad de desreferencia de puntero no fiable y escalado de privilegios en KERedirect en Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) podría permitir que un atacante local escale privilegios en instalaciones vulnerables. El problema resulta de la falta de una función de validación adecuada en el búfer de desplazamiento 0x6eDC proporcionado por el usuario. • http://www.securityfocus.com/bid/105757 https://esupport.trendmicro.com/en-US/home/pages/technical-support/1121296.aspx https://esupport.trendmicro.com/solution/ja-jp/1121350.aspx https://www.zerodayinitiative.com/advisories/ZDI-18-1295 • CWE-476: NULL Pointer Dereference •