PT-2017-11971 · Trend Micro · Trend Micro Control Manager

Rgod

·

Published

2017-08-02

·

Updated

2017-08-06

·

CVE-2017-11385

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Control Manager version 6.0
Description The issue is related to a SQL injection that causes remote code execution due to a lack of proper user input validation in the cmdHandlerStatusMonitor.dll module. This occurs when executing a specific opcode, 0x6b1b.
Recommendations For Trend Micro Control Manager version 6.0, update the software to a version that includes proper user input validation to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the cmdHandlerStatusMonitor.dll module to minimize the risk of exploitation.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11385
ZDI-17-495

Affected Products

Trend Micro Control Manager