CVE-2019-14685
Severity CVSS v4.0:
Pending analysis
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
21/08/2019
Last modified:
24/08/2020
Description
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:trendmicro:antivirus_\+_security_2019:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:internet_security_2019:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:maximum_security_2019:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:premium_security_2019:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/154200/Trend-Maximum-Security-2019-Unquoted-Search-Path.html
- http://seclists.org/fulldisclosure/2019/Aug/26
- https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123420.aspx
- https://medium.com/sidechannel-br/vulnerabilidade-no-trend-micro-maximum-security-2019-permite-a-escala%C3%A7%C3%A3o-de-privil%C3%A9gios-no-windows-471403d53b68



