ID |
CVE-2018-10358
|
Sažetak |
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. |
Reference |
|
CVSS |
Base: | 5.4 |
Impact: | 7.8 |
Exploitability: | 3.4 |
|
Pristup |
Vektor | Složenost | Autentikacija |
LOCAL |
MEDIUM |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
NONE |
PARTIAL |
COMPLETE |
|
CVSS vektor |
AV:L/AC:M/Au:N/C:N/I:P/A:C |
Zadnje važnije ažuriranje |
03-10-2019 - 00:03 |
Objavljeno |
08-06-2018 - 14:29 |