PT-2016-6708 · Trend Micro · Trend Micro Deep Discovery Inspector

Korpritzombie

·

Published

2016-06-22

·

Updated

2016-11-28

·

CVE-2016-5840

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro Deep Discovery Inspector versions 3.7 through 3.8 SP2 (3.82)
Description The issue allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header in the hotfix upload.cgi component.
Recommendations For versions 3.7 through 3.8 SP2 (3.82), as a temporary workaround, consider restricting access to the hotfix upload.cgi component until a patch is available. Avoid using shell metacharacters in the filename parameter of the Content-Disposition header in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-5840
ZDI-16-373

Affected Products

Trend Micro Deep Discovery Inspector