Vulnerability CVE-2017-9034


Published: 2017-05-25   Modified: 2017-05-26

Description:
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Trend Micro ServerProtect Disclosure / CSRF / XSS
Multiple
26.05.2017

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Trendmicro -> Serverprotect 

 References:
http://packetstormsecurity.com/files/142645/Trend-Micro-ServerProtect-Disclosure-CSRF-XSS.html
http://seclists.org/fulldisclosure/2017/May/91
http://www.securitytracker.com/id/1038548
https://success.trendmicro.com/solution/1117411
https://www.coresecurity.com/advisories/trend-micro-serverprotect-multiple-vulnerabilities

Copyright 2021, cxsecurity.com

 

Back to Top