CVE-2018-3608

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
06/07/2018
Last modified:
28/08/2018

Description

A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:antivirus_\+_security:*:*:*:*:*:*:*:* 12.0.1191 (including)
cpe:2.3:a:trendmicro:internet_security:*:*:*:*:*:*:*:* 12.0.1191 (including)
cpe:2.3:a:trendmicro:maximum_security:*:*:*:*:*:*:*:* 12.0.1191 (including)
cpe:2.3:a:trendmicro:premium_security:*:*:*:*:*:*:*:* 12.0.1191 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:11.0:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:12.0:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan_monthly:11.0:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan_monthly:12.0:*:*:*:*:*:*:*