Unrated severityNVD Advisory· Published Apr 1, 2009· Updated Apr 23, 2026
CVE-2009-0686
CVE-2009-0686
Description
The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory.
Affected products
4cpe:2.3:a:trendmicro:internet_security:2008:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:trendmicro:internet_security:2008:*:*:*:*:*:*:*
- cpe:2.3:a:trendmicro:internet_security:2008:-:pro:*:*:*:*:*
- cpe:2.3:a:trendmicro:internet_security:2009:*:*:*:*:*:*:*
- cpe:2.3:a:trendmicro:internet_security:2009:-:pro:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- milw0rm.com/sploits/2009-trendmicro_local_expl_0day.zipnvdExploit
- www.securityfocus.com/bid/34304nvdExploit
- en.securitylab.ru/lab/PT-2009-09nvd
- www.securityfocus.com/archive/1/502314/100/0/threadednvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/49513nvd
- www.exploit-db.com/exploits/8322nvd
News mentions
0No linked articles in our index yet.