CVE-2018-10357
Trend Micro Endpoint Application Control FileDrop Directory Traversal Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. Authentication is required to exploit this vulnerability.
Una vulnerabilidad de salto de directorio en Trend Micro Endpoint Application Control 2.0 podría permitir que un atacante remoto ejecute código arbitrarias en instalaciones vulnerables debido a un error en el servlet FileDrop. Se requiere autenticación para explotar esta vulnerabilidad.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Endpoint Application Control. Authentication is required to exploit this vulnerability.
The specific flaw exists within the FileDrop servlet. When parsing filenames, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code under the context of administrator.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-24 CVE Reserved
- 2018-05-17 CVE Published
- 2024-07-18 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104355 | Third Party Advisory | |
https://www.zerodayinitiative.com/advisories/ZDI-18-469 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://success.trendmicro.com/solution/1119811 | 2018-06-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Endpoint Application Control Search vendor "Trendmicro" for product "Endpoint Application Control" | 2.0 Search vendor "Trendmicro" for product "Endpoint Application Control" and version "2.0" | - |
Affected
|