A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Antivirus_+_security | Trendmicro | * | 12.0 (including) |
| Internet_security | Trendmicro | * | 12.0 (including) |
| Maximum_security | Trendmicro | * | 12.0 (including) |
| Premium_security | Trendmicro | * | 12.0 (including) |