Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Zer0B4By

#39253de 53,638
7CVSS total
Vulnerabilidades · 1
PT-2017-13244
7.0
2017-09-27
Trend Micro · Trend Micro Officescan · CVE-2017-14088
**Name of the Vulnerable Software and Affected Versions** Trend Micro OfficeScan versions 11.0 and XG **Description** The issue allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the issue. **Recommendations** For Trend Micro OfficeScan versions 11.0 and XG, consider disabling the tmwfp.sys driver as a temporary workaround until a patch is available. Restrict access to the vulnerable system to minimize the risk of exploitation.