Trend Micro Control Manager 'Cas_LogDirectInsert.aspx' Arbitrary Account Creation Vulnerability
BID:48638
Info
Trend Micro Control Manager 'Cas_LogDirectInsert.aspx' Arbitrary Account Creation Vulnerability
| Bugtraq ID: | 48638 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2011 12:00AM |
| Updated: | Jul 11 2011 12:00AM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: |
Trend Micro Control Manager 5.5 Trend Micro Control Manager 5.0 |
| Not Vulnerable: | |
Discussion
Trend Micro Control Manager 'Cas_LogDirectInsert.aspx' Arbitrary Account Creation Vulnerability
Trend Micro Control Manager is prone to a vulnerability that lets an attacker create an arbitrary account.
Successful exploits will allow remote attackers to gain access to the affected application and execute arbitrary code.
Trend Micro Control Manager 5.0 and 5.5 are vulnerable; other versions may also be affected.
Trend Micro Control Manager is prone to a vulnerability that lets an attacker create an arbitrary account.
Successful exploits will allow remote attackers to gain access to the affected application and execute arbitrary code.
Trend Micro Control Manager 5.0 and 5.5 are vulnerable; other versions may also be affected.
Exploit / POC
Trend Micro Control Manager 'Cas_LogDirectInsert.aspx' Arbitrary Account Creation Vulnerability
An attacker can exploit this issue with readily available network tools.
An attacker can exploit this issue with readily available network tools.
Solution / Fix
Trend Micro Control Manager 'Cas_LogDirectInsert.aspx' Arbitrary Account Creation Vulnerability
Solution:
Updates are available. Please see the references for more details.
Trend Micro Control Manager 5.5
Solution:
Updates are available. Please see the references for more details.
Trend Micro Control Manager 5.5
-
Trend Micro TMCM-5.5-B1250-Repack3.zip
http://downloadcenter.trendmicro.com/index.php?regs=NABU&clk=latest&cl kval=1763&lang_loc=1
References
Trend Micro Control Manager 'Cas_LogDirectInsert.aspx' Arbitrary Account Creation Vulnerability
References:
References:
- [Vulnerability Confirmation] CasLogDirectInsertHandler.cs can be used to execute (Trend Micro)
- Trend Micro Control Manager Homepage (Trend Micro)
- ZDI-11-234: Trend Micro Control Manager CasLogDirectInsertHandler.cs Remote Cod (TippingPoint Zero Day Initiative)