Trend Micro ScanMail for Exchange CVE-2017-14092 Cross Site Request Forgery Vulnerability
BID:102237
Info
Trend Micro ScanMail for Exchange CVE-2017-14092 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 102237 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-14092 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2017 12:00AM |
| Updated: | Dec 15 2017 12:00AM |
| Credit: | Leandro Barragan and Maximilian Vidal for Core Security Consulting |
| Vulnerable: |
Trend Micro ScanMail for Microsoft Exchange 12.0 |
| Not Vulnerable: | |
Discussion
Trend Micro ScanMail for Exchange CVE-2017-14092 Cross Site Request Forgery Vulnerability
Trend Micro ScanMail for Exchange is prone to cross-site request-forgery vulnerability because the application does not perform validity checks to verify HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions. This may lead to further attacks.
ScanMail for Exchange 12.0 is vulnerable.
Trend Micro ScanMail for Exchange is prone to cross-site request-forgery vulnerability because the application does not perform validity checks to verify HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions. This may lead to further attacks.
ScanMail for Exchange 12.0 is vulnerable.
Exploit / POC
Trend Micro ScanMail for Exchange CVE-2017-14092 Cross Site Request Forgery Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Trend Micro ScanMail for Exchange CVE-2017-14092 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Trend Micro ScanMail for Exchange CVE-2017-14092 Cross Site Request Forgery Vulnerability
References:
References:
- Trend Micro Homepage (Trend Micro)
- Cross-Site Request Forgery Protection (coresecurity)
- trendmicro advisory (trendmicro)