A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://success.trendmicro.com/solution/000287819 | vendor advisory |
https://success.trendmicro.com/solution/000287820 | vendor advisory |
https://success.trendmicro.com/jp/solution/000287796 | vendor advisory |
https://success.trendmicro.com/jp/solution/000287815 | vendor advisory |