Trend Micro ScanMail for Exchange CVE-2017-14091 Security Bypass Vulnerability
BID:102239
Info
Trend Micro ScanMail for Exchange CVE-2017-14091 Security Bypass Vulnerability
| Bugtraq ID: | 102239 |
| Class: | Design Error |
| CVE: |
CVE-2017-14091 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2017 12:00AM |
| Updated: | Dec 15 2017 12:00AM |
| Credit: | Leandro Barragan and Maximilian Vidal for Core Security Consulting |
| Vulnerable: |
Trend Micro ScanMail for Microsoft Exchange 12.0 |
| Not Vulnerable: |
Trend Micro Deep Discovery Director 1.1 (Build 1249) |
Discussion
Trend Micro ScanMail for Exchange CVE-2017-14091 Security Bypass Vulnerability
Trend Micro ScanMail for Exchange is prone to a security-bypass vulnerability.
Successfully exploiting this issue may allow attackers to bypass certain security restrictions and perform unauthorized actions. This may lead to other attacks.
ScanMail for Exchange 12.0 is vulnerable.
Trend Micro ScanMail for Exchange is prone to a security-bypass vulnerability.
Successfully exploiting this issue may allow attackers to bypass certain security restrictions and perform unauthorized actions. This may lead to other attacks.
ScanMail for Exchange 12.0 is vulnerable.
Solution / Fix
Trend Micro ScanMail for Exchange CVE-2017-14091 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Trend Micro ScanMail for Exchange CVE-2017-14091 Security Bypass Vulnerability
References:
References:
- Trend Micro Homepage (Trend Micro)
- coresecurity advisory (coresecurity)
- trendmicro advisory (trendmicro)