VulnerabilityModified
CVE-2017-11392
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations.
HIGH 8.8EPSS 33.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 33.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 33.76% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- trendmicro/interscan messaging security virtual appliance
- Source
- security@trendmicro.com
References
- http://www.securityfocus.com/bid/100075
- http://www.zerodayinitiative.com/advisories/ZDI-17-504Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/1117723Vendor Advisory
- http://www.securityfocus.com/bid/100075
- http://www.zerodayinitiative.com/advisories/ZDI-17-504Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/1117723Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.