CVE-2017-5565 Details
Description
Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Trend Micro process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://cybellum.com/doubleagent-taking-full-control-antivirus/ | CVE | Third Party Advisory |
| http://cybellum.com/doubleagentzero-day-code-injection-and-persistence-technique/ | CVE | Technical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/97031 | CVE | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038206 | CVE | |
| http://cybellum.com/doubleagent-taking-full-control-antivirus/ | [email protected] | Third Party Advisory |
| http://cybellum.com/doubleagentzero-day-code-injection-and-persistence-technique/ | [email protected] | Technical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/97031 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038206 | [email protected] | |
| https://success.trendmicro.com/solution/1116957 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| trendmicro antivirus+ | <= 11.1.1005 |
CPE
Remediation
| |
| trendmicro internet security | <= 11.1.1005 |
CPE
Remediation
| |
| trendmicro maximum security | <= 11.1.1005 |
CPE
Remediation
| |
| trendmicro premium security | <= 11.1.1005 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Jul 11, 2017 | CVE Modified | [email protected] |
| Mar 30, 2017 | Initial Analysis | [email protected] |
| Mar 25, 2017 | CVE Modified | [email protected] |