| ID |
CVE-2018-10358
|
| Sažetak |
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. |
| Reference |
|
| CVSS |
| Base: | 5.4 |
| Impact: | 7.8 |
| Exploitability: | 3.4 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| LOCAL |
MEDIUM |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| NONE |
PARTIAL |
COMPLETE |
|
| CVSS vektor |
AV:L/AC:M/Au:N/C:N/I:P/A:C |
| Zadnje važnije ažuriranje |
03-10-2019 - 00:03 |
| Objavljeno |
08-06-2018 - 14:29 |