CVE-2016-8585: Critical severity trend micro threat discovery appliance vulnerability
adminsystime.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8585?
CVE-2016-8585 has a high severity rating due to the ability for remote authenticated users to execute arbitrary code as the root user.
How do I fix CVE-2016-8585?
To fix CVE-2016-8585, update the Trend Micro Threat Discovery Appliance to version 2.6.1063 or later.
Who is affected by CVE-2016-8585?
CVE-2016-8585 affects users of Trend Micro Threat Discovery Appliance versions 2.6.1062r1 and earlier.
What type of attack does CVE-2016-8585 facilitate?
CVE-2016-8585 facilitates remote code execution attacks by allowing the exploitation of shell metacharacters in the timezone parameter.
Is authentication required to exploit CVE-2016-8585?
Yes, exploitation of CVE-2016-8585 requires remote authentication as a user of the Trend Micro Threat Discovery Appliance.