A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://esupport.trendmicro.com/en-US/home/pages/technical-support/1120742.aspx | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-18-961/ | third party advisory vdb entry |