CVE-2018-3608: Trend Micro Antivirus + Security

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.

Affected products

  • Trend Micro Antivirus + Security: up to and including 12.0.1191
  • Trend Micro Internet Security: up to and including 12.0.1191
  • Trend Micro Maximum Security: up to and including 12.0.1191
  • Trend Micro OfficeScan: version 11.0 only; version 12.0 only
  • Trend Micro OfficeScan Monthly: version 11.0 only; version 12.0 only
  • Trend Micro Premium Security: up to and including 12.0.1191

Published 2018-07-06. Last modified 2026-06-17.