Trend Micro OfficeScan TMTDI Module Local Privilege Escalation

high Nessus Plugin ID 50831

Language:

Synopsis

The remote host contains an application that is affected by a local privilege escalation issue.

Description

The remote host is either running Trend Micro OfficeScan or Trend Micro OfficeScan Client. The TMTDI module included with the installed version is affected by an unspecified vulnerability, which could allow a local attacker to execute arbitrary code on the remote system.

Solution

- v10.0 - Upgrade to Service Pack 1 Patch 2, and apply critical patch 2820.

- v10.5 - Apply critical patch 1161.

See Also

http://www.trendmicro.com/ftp/documentation/readme/Readme_2820.txt

http://www.trendmicro.com/ftp/documentation/readme/Readme_1161.txt

Plugin Details

Severity: High

ID: 50831

File Name: trendmicro_officescan_tmtdi_priv_escalation.nasl

Version: 1.6

Type: local

Agent: windows

Family: Windows

Published: 11/29/2010

Updated: 8/7/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:trend_micro:officescan

Required KB Items: SMB/Registry/Enumerated

Exploit Ease: No known exploits are available

Patch Publication Date: 11/9/2010

Vulnerability Publication Date: 11/9/2010

Reference Information

BID: 45034

Secunia: 42370