Showing 3 vulnerabilities on this page for Trend Micro Anti-Threat Toolkit (ATTK)

Signals CISA KEV Ransomware Nuclei
Trend Micro vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vu

CWE-20Aug 5, 2020
CVSS6.7v3.1EPSS0.656%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.

CVSS7.8v3.1EPSS4.62%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.

CWE-20CWE-427Oct 21, 2019
CVSS7.8v3.1EPSS12.9%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX