Trend Micro AntiVirus Scan Engine TMComm Local Privilege Escalation Vulnerability

Trend Micro's 'VsapiNI.sys' antivirus scan engine is prone to a local privilege-escalation vulnerability.

An attacker can exploit this issue to obtain SYSTEM privileges. A successful attack can result in the complete compromise of the affected computer.

The following software is vulnerable; other software and versions using the scan engine may also be affected:

Trend Micro's PC-Cillin Internet Security 2007
TmComm.sys version
VsapiNI.sys (scan engine) version 3.320.0.100
Trend Micro Antivirus 2007
Trend Micro Anti-Spyware for SMB 3.2 SP1
Trend Micro Anti-Spyware for Consumer 3.5
Trend Micro Anti-Spyware for Enterprise 3.0 SP2
Client / Server / Messaging Security for SMB 3.5
Damage Cleanup Services 3.2
Anti-Rootkit Common Module (RCM)


Privacy Statement
Copyright 2010, SecurityFocus