CVE Vulnerabilities

CVE-2018-10508

Published: Jun 12, 2018 | Modified: Oct 03, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissions on vulnerable installations. An attacker must already have at least guest privileges in order to exploit this vulnerability.

Affected Software

Name Vendor Start Version End Version
Officescan Trendmicro 11.0-sp1 (including) 11.0-sp1 (including)
Officescan Trendmicro xg (including) xg (including)
Officescan Trendmicro xg-sp1 (including) xg-sp1 (including)

References