Back

CVE-2018-3608

CRITICAL

A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.

Published: Jul 6, 2018 Modified: Jun 17, 2026
CWE-94

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (8)

Vendor Product Version
trendmicro antivirus_\+_security *
trendmicro internet_security *
trendmicro maximum_security *
trendmicro premium_security *
trendmicro officescan 11.0
trendmicro officescan 12.0
trendmicro officescan_monthly 11.0
trendmicro officescan_monthly 12.0

GitHub Security Advisory GHSA-4wvj-8v7h-xg58

A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below)...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.40%

Top 12% most likely to be exploited

Threat Score 40.2 / 100

Data Sources

NVD EPSS GitHub