CVE-2017-11385
Trend Micro Control Manager cmdHandlerStatusMonitor SQL Injection Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-4545.
Una vulnerabilidad de inyección SQL en Trend Micro Control Manager 6.0 permite la ejecución de código remoto cuando se ejecuta opcode 0x6b1b por no haber una validación de los datos de entrada del usuario correcta en cmdHandlerStatusMonitor.dll. Anteriormente esta vulnerabilidad tenía el código ZDI-CAN-4545.
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Trend Micro Control Manager. Authentication is not required to exploit this vulnerability.
The specific flaw exists within cmdHandlerStatusMonitor.dll when executing opcode 0x6b1b. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the database.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-17 CVE Reserved
- 2017-08-02 CVE Published
- 2024-08-05 CVE Updated
- 2024-11-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100078 | Vdb Entry | |
http://www.securitytracker.com/id/1039049 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-17-495 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://success.trendmicro.com/solution/1117722 | 2017-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Control Manager Search vendor "Trendmicro" for product "Control Manager" | 6.0 Search vendor "Trendmicro" for product "Control Manager" and version "6.0" | - |
Affected
|