PT-2018-9843 · Trend Micro · Trend Micro Endpoint Application Control

Published

2018-05-17

·

Updated

2018-06-26

·

CVE-2018-10357

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Trend Micro Endpoint Application Control version 2.0
Description: A directory traversal issue exists due to a flaw in the FileDrop servlet, allowing a remote attacker to execute arbitrary code on vulnerable installations. Authentication is required to exploit this issue.
Recommendations: For Trend Micro Endpoint Application Control version 2.0, consider disabling the FileDrop servlet as a temporary workaround until a patch is available. Restrict access to the FileDrop servlet to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10357
ZDI-18-469

Affected Products

Trend Micro Endpoint Application Control