CVE-2019-9491
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 12.94% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- trendmicro/anti-threat toolkit
- Source
- security@trendmicro.com
References
- http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-ANTI-THREAT-TOOLKIT-%28ATTK%29-REMOTE-CODE-EXECUTION.txt
- http://packetstormsecurity.com/files/156160/TrendMicro-Anti-Threat-Toolkit-Improper-Fix.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Oct/42Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2020/Jan/50Exploit, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Oct/30Exploit, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/55Exploit, Mailing List, Third Party Advisory
- https://success.trendmicro.com/solution/000149878Vendor Advisory
- http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-ANTI-THREAT-TOOLKIT-%28ATTK%29-REMOTE-CODE-EXECUTION.txt
- http://packetstormsecurity.com/files/156160/TrendMicro-Anti-Threat-Toolkit-Improper-Fix.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Oct/42Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2020/Jan/50Exploit, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Oct/30Exploit, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/55Exploit, Mailing List, Third Party Advisory
- https://success.trendmicro.com/solution/000149878Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.