CVE-2003-1343: High severity Trend Micro ScanMail vulnerability
Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smgSmxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trend Micro ScanMail for Exchange (SMEX)to a version that resolves this vulnerability.Fixed in 3.81 - Upgrade
Upgrade
Trend Micro ScanMail for Exchange (SMEX)to a version that resolves this vulnerability.Fixed in 6.1 - Compensating control
Restrict network access to the ScanMail web management interface to trusted IP addresses (for example via firewall rules or network ACLs) to prevent remote exploitation of the 'vcc' backdoor.
- Operational
Search installed SMEX instances for the file smg_Smxcfg30.exe and inspect configuration and binaries for a backdoor account accessible via the 'vcc' parameter. Search for the literal value '3560121183d3'. If the backdoor account or that vcc value is found, remove/disable the account, rotate web management interface credentials, and audit logs for possible unauthorized access.
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1343?
CVE-2003-1343 is considered a critical vulnerability due to the potential for unauthorized access to the web management interface.
How do I fix CVE-2003-1343?
To fix CVE-2003-1343, upgrade Trend Micro ScanMail for Exchange to version 3.81 or 6.1 or later.
What systems are affected by CVE-2003-1343?
CVE-2003-1343 affects Trend Micro ScanMail for Exchange versions prior to 3.81 and supports up to version 6.0.
Can CVE-2003-1343 allow attackers to access sensitive information?
Yes, CVE-2003-1343 could allow remote attackers to gain access to sensitive information through the back door account.
What steps should I take if I am currently using an affected version for CVE-2003-1343?
If using an affected version, immediately update to a secure version to mitigate potential exploitation.