CVE-2019-9492

HIGH

Trend Micro OfficeScan <11.0 SP1-XG - RCE

Title source: llm
STIX 2.1

Description

A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access to the vulnerable system.

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 28.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (2)
trendmicro/officescan 11.0 sp1
trendmicro/officescan xg
Published Jul 26, 2019
Tracked Since Feb 18, 2026