CVE-2018-10508: Trend Micro OfficeScan

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissions on vulnerable installations. An attacker must already have at least guest privileges in order to exploit this vulnerability.

Affected products

  • Trend Micro OfficeScan: version 11.0 only; version xg only

Published 2018-06-12. Last modified 2026-06-17.