CVE-2009-0686 describes a local privilege escalation vulnerability in the TrendMicro Activity Monitor Module (tmactmon.sys) affecting Trend Micro Internet Pro and Security Pro 2008 and 2009. An attacker can craft an IRP in an IOCTL request to overwrite memory, leading to full compromise of the system. This vulnerability has a CVSS score of 7.2, indicating high severity with low attack complexity and requiring local access. While not listed on the KEV catalog, an exploit for this vulnerability is publicly available on ExploitDB, though there is minimal community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2008CPE matchmatch criteria | cpe:2.3:a:trendmicro:internet_security:2008:*:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:a:trendmicro:internet_security:2008:-:pro:*:*:*:*:* | ||
2009CPE matchmatch criteria | cpe:2.3:a:trendmicro:internet_security:2009:*:*:*:*:*:*:* | ||
2009CPE matchmatch criteria | cpe:2.3:a:trendmicro:internet_security:2009:-:pro:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.