CVE Vulnerabilities

CVE-2018-10508

Published: Jun 12, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissions on vulnerable installations. An attacker must already have at least guest privileges in order to exploit this vulnerability.

Affected Software

NameVendorStart VersionEnd Version
OfficescanTrendmicro11.0-sp1 (including)11.0-sp1 (including)
OfficescanTrendmicroxg (including)xg (including)
OfficescanTrendmicroxg-sp1 (including)xg-sp1 (including)

References