Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Zer0B4By

#41634of 56,333
7Total CVSS
Vulnerabilities · 1
PT-2017-13244
7.0
2017-09-27
Trend Micro · Trend Micro Officescan · CVE-2017-14088
**Name of the Vulnerable Software and Affected Versions** Trend Micro OfficeScan versions 11.0 and XG **Description** The issue allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the issue. **Recommendations** For Trend Micro OfficeScan versions 11.0 and XG, consider disabling the tmwfp.sys driver as a temporary workaround until a patch is available. Restrict access to the vulnerable system to minimize the risk of exploitation.