vendor:
OfficeScan Client
by:
msd0pe
7.5
CVSS
HIGH
ACL Service LPE
CWE
Product Name: OfficeScan Client
Affected Version From: Versions <= 10.0
Affected Version To: Versions <= 10.0
Patch Exists: NO
Related CWE:
CPE: CPE not provided
Platforms Tested: Windows
2023
Trend Micro OfficeScan Client 10.0 – ACL Service LPE
Versions =< 10.0 of Trend Micro OfficeScan Client contain wrong ACL rights on the OfficeScan client folder, allowing attackers to escalate privileges to the system level through the services. This vulnerability does not require any privileged access.
Mitigation:
No mitigation or remediation information provided.