Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Trend Micro process via a "DoubleAgent" attack
Published Mar 21, 2017
6.7
MEDIUMCVSS 3.0
EPSS 0.70%
Description
Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Trend Micro process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.
Affected products
No data.
- ≤ 11.1.1005
- ≤ 11.1.1005
- ≤ 11.1.1005
- ≤ 11.1.1005
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.70% (0.00696) | 51.25th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.70% (0.00696) | 51.54th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.40% (0.01404) | 72.03th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.40% (0.01404) | 45.81th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.97% (0.00974) | 26.08th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.97% (0.00974) | 0.00th | v1 |
References (5)
- http://cybellum.com/doubleagent-taking-full-control-antivirus/ x_refsource_MISCThird Party Advisory
- http://cybellum.com/doubleagentzero-day-code-injection-and-persistence-technique/ x_refsource_MISCTechnical DescriptionThird Party Advisory
- http://www.securityfocus.com/bid/97031 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038206 vdb-entryx_refsource_SECTRACK
- https://success.trendmicro.com/solution/1116957 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://cybellum.com/doubleagent-taking-full-control-antivirus/ | x_refsource_MISCThird Party Advisory | |
| http://cybellum.com/doubleagentzero-day-code-injection-and-persistence-technique/ | x_refsource_MISCTechnical DescriptionThird Party Advisory | |
| http://www.securityfocus.com/bid/97031 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1038206 | vdb-entryx_refsource_SECTRACK | |
| https://success.trendmicro.com/solution/1116957 | Vendor Advisory |
Change history (0)
No recorded changes yet.