Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://helpcenter.trendmicro.com/en-us/article/TMKA-10337 | vendor advisory |
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1231 | third party advisory |