Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpr5-522c-rj7q

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.

Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.

EPSS

Процентиль: 29%
0.00108
Низкий

7 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7
nvd
больше 8 лет назад

Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.

EPSS

Процентиль: 29%
0.00108
Низкий

7 High

CVSS3

Дефекты

CWE-119