Trend Micro OfficeScan Proxy CVE-2017-11393 Command Injection Vulnerability
BID:100127
Info
Trend Micro OfficeScan Proxy CVE-2017-11393 Command Injection Vulnerability
| Bugtraq ID: | 100127 |
| Class: | Design Error |
| CVE: |
CVE-2017-11393 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2017 12:00AM |
| Updated: | Aug 02 2017 12:00AM |
| Credit: | Steven Seeley of Source Incite. |
| Vulnerable: |
Trend Micro OfficeScan XG (12.0) Trend Micro OfficeScan 11.0 SP1 |
| Not Vulnerable: |
Trend Micro OfficeScan XG CP 1641 r1 Trend Micro OfficeScan 11.0 SP1 CP 6392 r1 |
Discussion
Trend Micro OfficeScan Proxy CVE-2017-11393 Command Injection Vulnerability
Trend Micro OfficeScan Proxy is prone to a remote command-injection vulnerability.
An attacker may exploit this issue to execute arbitrary code with root privileges; this may aid in further attacks.
Trend Micro OfficeScan 11.0 SP1 and XG (12.0) versions are affected.
Trend Micro OfficeScan Proxy is prone to a remote command-injection vulnerability.
An attacker may exploit this issue to execute arbitrary code with root privileges; this may aid in further attacks.
Trend Micro OfficeScan 11.0 SP1 and XG (12.0) versions are affected.
Exploit / POC
Trend Micro OfficeScan Proxy CVE-2017-11393 Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Trend Micro OfficeScan Proxy CVE-2017-11393 Command Injection Vulnerability
References:
References: