CVE-2017-14088
Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
- CVSS 3.0
- 7.0 HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- trendmicro/officescan · trendmicro/officescan xg
- Source
- security@trendmicro.com
References
- http://www.securityfocus.com/bid/101070Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039500Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-17-828Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-17-829Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/1118372Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101070Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039500Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-17-828Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-17-829Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/1118372Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.