CVE-2009-0686
Last modified
CVE-2009-0686 is a vulnerability of currently unknown severity. The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Internet Security | 2008 |
| Trendmicro | Internet Security | 2009 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0686?
How severe is CVE-2009-0686?
How do I fix CVE-2009-0686?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0677avatarlist.php in the Your Account module, reached through m…
- CVE-2009-0678images/captcha.php in RavenNuke 2.30 allows remote attackers…
- CVE-2009-0679Cross-site scripting (XSS) vulnerability in the Your Account…
- CVE-2009-0680cgi-bin/welcome/VPN_only in the web interface in Netgear SSL…
- CVE-2009-0681PGP Desktop before 9.10 allows local users to (1) cause a de…
- CVE-2009-0682vetmonnt.sys in CA Internet Security Suite r3, vetmonnt.sys …
- CVE-2009-0687The pf_test_rule function in OpenBSD Packet Filter (PF), as …
- CVE-2009-0688Multiple buffer overflows in the CMU Cyrus SASL library befo…
- CVE-2009-0689Array index error in the (1) dtoa implementation in dtoa.c (…
- CVE-2009-0690The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 …
- CVE-2009-0691The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 …
- CVE-2009-0692Stack-based buffer overflow in the script_write_params metho…
Are you affected by CVE-2009-0686?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
