CVE-2018-18329

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
23/10/2018
Last modified:
04/12/2018

Description

A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6F4E offset user-supplied buffer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:antivirus_for_mac_2017:*:*:*:*:*:*:*:* 7.0 (including) 7.1.1124 (including)
cpe:2.3:a:trendmicro:antivirus_for_mac_2018:*:*:*:*:*:*:*:* 8.0 (including) 8.0.3082 (including)
cpe:2.3:a:trendmicro:antivirus_for_mac_2019:*:*:*:*:*:*:*:* 9.0 (including) 9.0.1356 (including)