Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:trendmicro:antivirus_\\+_security:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C163595-996C-4B71-96A4-02729066F75A", "versionEndIncluding": "12.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:trendmicro:internet_security:*:*:*:*:*:*:*:*", "matchCriteriaId": "9ABDF487-D7B5-4A1C-9097-E4CD0B2EE31C", "versionEndIncluding": "12.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:trendmicro:maximum_security:*:*:*:*:*:*:*:*", "matchCriteriaId": "A362B140-67F1-439E-B901-C525D2560522", "versionEndIncluding": "12.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:trendmicro:premium_security:*:*:*:*:*:*:*:*", "matchCriteriaId": "171B3754-A310-409E-9CB3-423D62BC99EF", "versionEndIncluding": "12.0", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}], "descriptions": [{"lang": "en", "value": "A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability."}, {"lang": "es", "value": "Una vulnerabilidad de deserializaci\u00f3n de datos no fiables y de escalado de privilegios en productos Trend Micro Security 2018 (Consumer) podr\u00eda permitir que un atacante local escale privilegios en instalaciones vulnerables. En primer lugar, un atacante debe obtener la habilidad para ejecutar c\u00f3digo de bajos privilegios en el sistema objetivo para explotar esta vulnerabilidad."}], "id": "CVE-2018-10513", "lastModified": "2024-11-21T03:41:28.370", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": {"accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 7.2, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "version": "2.0"}, "exploitabilityScore": 3.9, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV30": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0"}, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2018-08-30T19:29:00.417", "references": [{"source": "security@trendmicro.com", "tags": ["Vendor Advisory"], "url": "https://esupport.trendmicro.com/en-US/home/pages/technical-support/1120742.aspx"}, {"source": "security@trendmicro.com", "tags": ["Third Party Advisory", "VDB Entry"], "url": "https://www.zerodayinitiative.com/advisories/ZDI-18-961/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://esupport.trendmicro.com/en-US/home/pages/technical-support/1120742.aspx"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory", "VDB Entry"], "url": "https://www.zerodayinitiative.com/advisories/ZDI-18-961/"}], "sourceIdentifier": "security@trendmicro.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-502"}], "source": "nvd@nist.gov", "type": "Primary"}]}