CVE-2018-10358 - CERT CVE
ID CVE-2018-10358
Sažetak A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Reference
CVSS
Base: 5.4
Impact: 7.8
Exploitability:3.4
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL COMPLETE
CVSS vektor AV:L/AC:M/Au:N/C:N/I:P/A:C
Zadnje važnije ažuriranje 03-10-2019 - 00:03
Objavljeno 08-06-2018 - 14:29