PT-2017-11970 · Trend Micro · Trend Micro Control Manager
Rgod
·
Published
2017-08-02
·
Updated
2017-08-08
·
CVE-2017-11384
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Control Manager version 6.0
Description
The issue is related to a lack of proper user input validation in the mdHandlerLicenseManager.dll module, which can lead to remote code execution when executing a specific opcode, 0x3b21. This occurs due to an SQL injection vulnerability.
Recommendations
For Trend Micro Control Manager version 6.0, update the software to a version that includes proper user input validation to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the mdHandlerLicenseManager.dll module to minimize the risk of exploitation.
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Control Manager