CVE-2009-0686

TrendMicro Activity Monitor Module <2.52.0.1002 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0686. PoCs published by b1@ckeYe.

AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in Trend Micro Internet Security Pro 2009's tmactmon.sys driver. It leverages improper IOCTL handling to execute arbitrary code in kernel space.

Description

The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory.

Exploits (1)

exploitdb WORKING POC VERIFIED
by b1@ckeYe · textlocalwindows
https://www.exploit-db.com/exploits/8322

This exploit targets a privilege escalation vulnerability in Trend Micro Internet Security Pro 2009's tmactmon.sys driver. It leverages improper IOCTL handling to execute arbitrary code in kernel space.

Classification
Working Poc 80%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: Trend Micro Internet Security Pro 2009
No auth needed
Prerequisites: Local access to the system · Presence of Trend Micro Internet Security Pro 2009 with tmactmon.sys driver
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8322
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021955
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34304
Various Sources x_refsource_misc
http://en.securitylab.ru/lab/PT-2009-09
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49513
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502314/100/0/threaded

Scores

EPSS 0.0013
EPSS Percentile 31.9%

Details

CWE
CWE-399
Status published
Products (2)
trendmicro/internet_security 2008 (2 CPE variants)
trendmicro/internet_security 2009 (2 CPE variants)
Published Apr 01, 2009
Tracked Since Feb 18, 2026