PT-2017-2910 · Trend Micro · Trend Micro Serverprotect For Linux

Published

2017-03-14

·

Updated

2021-09-09

·

CVE-2017-9034

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro ServerProtect for Linux version 3.0 before CP 1531
Description The issue exists due to insufficient input validation, allowing a remote attacker to modify arbitrary files or execute arbitrary code with root privileges by exploiting the failure to validate software updates.
Recommendations For Trend Micro ServerProtect for Linux version 3.0 before CP 1531, update to a version that includes CP 1531 or later to resolve the issue. As a temporary workaround, consider restricting access to software update mechanisms to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02235
CVE-2017-9034

Affected Products

Trend Micro Serverprotect For Linux