VYPR
Unrated severityNVD Advisory· Published Aug 30, 2018· Updated Aug 5, 2024

CVE-2018-10514

CVE-2018-10514

Description

A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A missing impersonation check in Trend Micro Maximum Security allows local attackers to escalate privileges to SYSTEM.

Vulnerability

The vulnerability exists in Trend Micro Maximum Security, part of the Trend Micro Security 2018 consumer product line. The flaw is in the coreServiceShell service when processing request ID 0x2ff0000b within the ID_AMSP_MASTER handler. The service fails to properly impersonate the client before executing sensitive operations, allowing a low-privileged attacker to perform actions with elevated privileges. Affected versions include Trend Micro Security 2018 (Consumer) products. [1]

Exploitation

An attacker must first obtain the ability to execute low-privileged code on the target system. The attacker then sends a crafted request to the coreServiceShell service using the specific request ID 0x2ff0000b. Due to the missing impersonation check, the service executes the requested operation with SYSTEM privileges. [1]

Impact

Successful exploitation allows the attacker to escalate privileges from a low-privileged user to SYSTEM, gaining full control over the affected system. This includes the ability to execute arbitrary code, install programs, and access or modify all data. [1]

Mitigation

The available reference does not disclose a specific fix or patched version. Users should consult Trend Micro's official advisory for updates. As of the publication date (August 30, 2018), no workaround is provided in the reference. [1]

References
  1. ZDI-18-962

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.