Trend Micro Security 2019 Security Bypass Protected Service Tampering
Posted by deepcore on January 18, 2020 – 1:08 am
Trend Micro Maximum Security is vulnerable to arbitrary code execution as it allows for creation of registry key to target a process running as SYSTEM. This can allow a malware to gain elevated privileges to take over and shutdown services that require SYSTEM privileges like Trend Micros “Asmp” service “coreServiceShell.exe” which does not allow Administrators to tamper with them. This could allow an attacker or malware to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. Note administrator privileges are required to exploit this vulnerability.
Post a reply
You must be logged in to post a comment.