Trend Micro Web Management Authentication Bypass Vulnerability

BID:30792

Info

Trend Micro Web Management Authentication Bypass Vulnerability

Bugtraq ID: 30792
Class: Design Error
CVE: CVE-2008-2433
Remote: Yes
Local: No
Published: Aug 22 2008 12:00AM
Updated: Aug 28 2008 06:46PM
Credit: Dyon Balding
Vulnerable: Trend Micro Worry-Free Business Security 5.0
Trend Micro OfficeScan 8.0
- Microsoft Windows 3.1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
- Novell Netware 4.11
- Novell Netware 4.1
Trend Micro OfficeScan 7.3
- Microsoft Windows 3.1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
- Novell Netware 4.11
- Novell Netware 4.1
Trend Micro OfficeScan 7.0
- Microsoft Windows 3.1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
- Novell Netware 4.11
- Novell Netware 4.1
Trend Micro Client/Server/Messaging Suite 3.6
- Microsoft Windows 3.1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
- Novell Netware 4.11
- Novell Netware 4.1
Trend Micro Client/Server/Messaging Suite 3.5
- Microsoft Windows 3.1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
- Novell Netware 4.11
- Novell Netware 4.1
Not Vulnerable:

Discussion

Trend Micro Web Management Authentication Bypass Vulnerability

Trend Micro Web Management is prone to an authentication-bypass vulnerability because of insufficient entropy used when creating session tokens.

Attackers can exploit this issue to gain administrative access to the application. Reports indicate that after gaining access to the management console, attackers may be able to execute arbitrary code by changing the configuration. Due to a lack of information, the context of the code execution is currently unknown. We will update this BID as more information emerges.

The following Trend Micro products are affected:

Trend Micro OfficeScan 7.0, 7.3 and 8.0
Worry-Free Business Security 5.0
Trend Micro Client/Server/Messaging Suite 3.5 and 3.6

Other versions of these products may also be affected.

Exploit / POC

Trend Micro Web Management Authentication Bypass Vulnerability

Attackers can use widely available tools to exploit this issue.

Solution / Fix

Trend Micro Web Management Authentication Bypass Vulnerability

Solution:
Trend Micro have released patches for OfficeScan 8.0 and Worry-Free Business Security 5.0. Reportedly, patches for other affected products will be released shortly. We will update this BID as more information emerges.


Trend Micro OfficeScan 8.0

Trend Micro Worry-Free Business Security 5.0

References

© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report