### [CVE-2019-14685](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14685) ![](https://img.shields.io/static/v1?label=Product&message=Trend%20Micro%20Security%20(Consumer)&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Local%20Privilege%20Escalation&color=brighgreen) ### Description A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service. ### POC #### Reference - http://packetstormsecurity.com/files/154200/Trend-Maximum-Security-2019-Unquoted-Search-Path.html - http://seclists.org/fulldisclosure/2019/Aug/26 - https://medium.com/sidechannel-br/vulnerabilidade-no-trend-micro-maximum-security-2019-permite-a-escala%C3%A7%C3%A3o-de-privil%C3%A9gios-no-windows-471403d53b68 #### Github No PoCs found on GitHub currently.