cve/2019/CVE-2019-14685.md

20 lines
993 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-14685](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14685)
![](https://img.shields.io/static/v1?label=Product&message=Trend%20Micro%20Security%20(Consumer)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Local%20Privilege%20Escalation&color=brighgreen)
### Description
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
### POC
#### Reference
- http://packetstormsecurity.com/files/154200/Trend-Maximum-Security-2019-Unquoted-Search-Path.html
- http://seclists.org/fulldisclosure/2019/Aug/26
- https://medium.com/sidechannel-br/vulnerabilidade-no-trend-micro-maximum-security-2019-permite-a-escala%C3%A7%C3%A3o-de-privil%C3%A9gios-no-windows-471403d53b68
#### Github
No PoCs found on GitHub currently.