Vulnerability Details CVE-2018-18328
A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation function on 0x6F6A offset user-supplied buffer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.4%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2018-18328
-
cpe:2.3:a:trendmicro:antivirus_for_mac_2017:7.0
-
cpe:2.3:a:trendmicro:antivirus_for_mac_2017:7.1.1124
-
cpe:2.3:a:trendmicro:antivirus_for_mac_2018:8.0
-
cpe:2.3:a:trendmicro:antivirus_for_mac_2018:8.0.3082
-
cpe:2.3:a:trendmicro:antivirus_for_mac_2019:9.0
-
cpe:2.3:a:trendmicro:antivirus_for_mac_2019:9.0.1356