The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. Please note than an attacker must already have local user privileges and access on the machine to exploit this vulnerability.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://helpcenter.trendmicro.com/en-us/article/TMKA-10336 | vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-603/ | vdb entry third party advisory |