PT-2017-11970 · Trend Micro · Trend Micro Control Manager

Rgod

·

Published

2017-08-02

·

Updated

2017-08-08

·

CVE-2017-11384

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Control Manager version 6.0
Description The issue is related to a lack of proper user input validation in the mdHandlerLicenseManager.dll module, which can lead to remote code execution when executing a specific opcode, 0x3b21. This occurs due to an SQL injection vulnerability.
Recommendations For Trend Micro Control Manager version 6.0, update the software to a version that includes proper user input validation to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the mdHandlerLicenseManager.dll module to minimize the risk of exploitation.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11384
ZDI-17-494

Affected Products

Trend Micro Control Manager