PT-2017-13235 · Trend Micro · Trend Micro Mobile Security

Mr_Me

+2

·

Published

2017-09-15

·

Updated

2017-09-29

·

CVE-2017-14078

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3
Description The issue allows remote attackers to execute arbitrary code on vulnerable installations. Multiple API endpoints are vulnerable to SQL Injection, including query installed applications, change ios setting, move group, eas agent check upgrade, notify devices to update, upload web app, update group, delete user, query event log, delete devices, notify devices to scan, add app category, export devices, search devices, get dep profile, remote wipe device, change device user, remote lock device, eas agent unregister, eas agent upload new devices, edit user, export eas devices, get moveto group list, locate device, get user list, move devices, invite devices, delete admin account, notify groups to scan, cancel command list, reinvite user, remove eas agent info, get device list brief by group, mdm register new connector, edit eas note, get device detail info, query user, add group, eas agent register, resend command list, get device location, broadcast group, get subgroup list, eas agent sync all devices, edit device, search user for report, notify groups to update, eas agent sync client info, broadcast devices, remote selective wipe device, show eas agent info, show eas devices, reset device passwd, search users for vpp, stop mirroring, remove command list, diagnose eas status, change user, eas agent command, invite devices, save eas agent setting, create db, get remote unlockstring, assign policy, delete group, search device invitations. Vulnerable parameters include application name, Device DeviceId, Id, SlinkId, AppFile, AdminName, Device DeviceGroupId, group id, Name, Device DeviceDeviceId, user name, LDAPAccount, CmdUUID, UserName, DeviceGroupId, id.
Recommendations For Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3, update to version 9.7 Patch 3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable API endpoints until a patch is available. Avoid using vulnerable parameters in the affected API endpoints until the issue is resolved.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14078
ZDI-17-737
ZDI-17-739
ZDI-17-740
ZDI-17-741
ZDI-17-742
ZDI-17-743
ZDI-17-744
ZDI-17-745
ZDI-17-746
ZDI-17-747
ZDI-17-748
ZDI-17-749
ZDI-17-750
ZDI-17-751
ZDI-17-753
ZDI-17-754
ZDI-17-755
ZDI-17-756
ZDI-17-757
ZDI-17-758
ZDI-17-759
ZDI-17-760
ZDI-17-761
ZDI-17-762
ZDI-17-763
ZDI-17-764
ZDI-17-765
ZDI-17-766
ZDI-17-768
ZDI-17-769
ZDI-17-770
ZDI-17-771
ZDI-17-772
ZDI-17-773
ZDI-17-775
ZDI-17-776
ZDI-17-777
ZDI-17-778
ZDI-17-779
ZDI-17-780
ZDI-17-781
ZDI-17-782
ZDI-17-783
ZDI-17-784
ZDI-17-786
ZDI-17-787
ZDI-17-788
ZDI-17-791
ZDI-17-792
ZDI-17-793
ZDI-17-794
ZDI-17-795
ZDI-17-796
ZDI-17-797
ZDI-17-798
ZDI-17-799
ZDI-17-800
ZDI-17-801
ZDI-17-802
ZDI-17-803
ZDI-17-804
ZDI-17-805
ZDI-17-806
ZDI-17-808
ZDI-17-809
ZDI-17-810

Affected Products

Trend Micro Mobile Security