CVE-2017-11394
critical · 9.8Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.
9.8
CVSS
66.8%
EPSS (exploit prob.)
99th
EPSS percentile
2017-08-03
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| trendmicro | officescan | 11.0 |
| trendmicro | officescan | 12.0 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/100130
- http://www.zerodayinitiative.com/advisories/ZDI-17-521
- https://success.trendmicro.com/solution/1117769
- https://www.exploit-db.com/exploits/42971/
- http://www.securityfocus.com/bid/100130
- http://www.zerodayinitiative.com/advisories/ZDI-17-521
- https://success.trendmicro.com/solution/1117769
- https://www.exploit-db.com/exploits/42971/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-11394