Page 2 of 32 results (0.009 seconds)

CVSS: 6.3EPSS: 0%CPEs: 3EXPL: 0

07 Jun 2018 — A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220078 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Una vulnerabilidad de escalado de privilegios por corrupción de pool en Trend Micro OfficeScan 11.0 SP1 y XG podría permitir que... • https://success.trendmicro.com/solution/1119961 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 4.7EPSS: 0%CPEs: 3EXPL: 0

07 Jun 2018 — A out-of-bounds read information disclosure vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within the processing of IOCTL 0x220004 by the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Una vulnerabilidad de divulgación de información por lectura fuera de límites en Trend Micro OfficeScan 11.0 SP1... • https://success.trendmicro.com/solution/1119961 • CWE-125: Out-of-bounds Read •

CVSS: 6.3EPSS: 0%CPEs: 3EXPL: 0

07 Jun 2018 — A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220008 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Una vulnerabilidad de escalado de privilegios por corrupción de pool en Trend Micro OfficeScan 11.0 SP1 y XG podría permitir que... • https://success.trendmicro.com/solution/1119961 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 6.3EPSS: 0%CPEs: 3EXPL: 0

07 Jun 2018 — A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Una vulnerabilidad de escalado de privilegios por corrupción de pool en Trend Micro OfficeScan 11.0 SP1 y XG podría permitir que... • https://success.trendmicro.com/solution/1119961 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.0EPSS: 0%CPEs: 8EXPL: 0

16 Feb 2018 — A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system. Una vulnerabilidad de secuestro de DLL en Trend Micro's User-Mode Hooking Module (UMH) podría permitir que un atacante ejecute código arbitrario en un sistema vulnerable. • http://www.securityfocus.com/bid/103096 • CWE-426: Untrusted Search Path •

CVSS: 9.8EPSS: 2%CPEs: 2EXPL: 4

01 Oct 2017 — An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues. Una vulnerabilidad de corrupción de memoria no autorizada en Trend Micro OfficeScan 11.0 y XG puede permitir que usuarios remotos no autenticados con acceso al servidor OfficeScan utilicen el archivo cgiShowClientAdm.exe y provoquen problemas de corrupción de memoria. TrendMicro Off... • https://packetstorm.news/files/id/144464 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.8EPSS: 2%CPEs: 2EXPL: 3

29 Sep 2017 — Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause the server disk space to be consumed with dump files from continuous HTTP requests. Vulnerabilidades de proceso remoto de inicio de preautorización en Trend Micro OfficeScan 11.0 y XG puede permitir que usuarios no autenticados con acceso al servidor OfficeS... • https://packetstorm.news/files/id/144401 • CWE-400: Uncontrolled Resource Consumption •

CVSS: 8.1EPSS: 6%CPEs: 2EXPL: 2

29 Sep 2017 — A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations. Una vulnerabilidad potencial de ataque Man-in-the-Middle (MitM) en Trend Micro OfficeScan 11.0 y XG permite a los atacantes ejecutar código arbitrario en instalaciones vulnerables. TrendMicro OfficeScan versions 11.0 and XG (12.0) suffer from a curl man-in-the-middle remote code execution vulnerability. • https://packetstorm.news/files/id/144400 •

CVSS: 7.5EPSS: 3%CPEs: 2EXPL: 5

29 Sep 2017 — A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages. Existe una vulnerabilidad de inyección de cabecera Host en Trend Micro OfficeScan XG (12.0) que puede permitir que un atacante suplante una cabecera Host específica, lo que le permitiría incluir enlaces arbitrarios que apunten a un sitio web malicioso con páginas... • https://packetstorm.news/files/id/144404 • CWE-20: Improper Input Validation •

CVSS: 5.3EPSS: 1%CPEs: 2EXPL: 4

29 Sep 2017 — Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules. Vulnerabilidades de divulgación de información en Trend Micro OfficeScan 11.0 y XG pueden permitir que los usuarios con acceso al servidor OfficeScan consulten el dominio NT o los módulos y la versión PHP del servidor. TrendMicro OfficeScan versions 11.0 and XG (12.0) suffer from NT domain and PHP in... • https://packetstorm.news/files/id/144402 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •