A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://esupport.trendmicro.com/en-US/home/pages/technical-support/1120237.aspx | vendor advisory |
http://esupport.trendmicro.com/support/vb/solution/ja-jp/1120144.aspx | vendor advisory |