CVE-2016-8588: High severity trend micro threat discovery appliance vulnerability
Published Apr 28, 2017
·Updated
The hotfixupload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
Affected Software
1 affected component
trendmicro Threat Discovery Appliance<=2.6.1062
Event History
Apr 28, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-8588?
CVE-2016-8588 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2016-8588?
To mitigate CVE-2016-8588, update the Trend Micro Threat Discovery Appliance to version 2.6.1062r2 or later.
3
Who is affected by CVE-2016-8588?
CVE-2016-8588 affects users of Trend Micro Threat Discovery Appliance version 2.6.1062r1 and earlier.
4
What type of vulnerability is CVE-2016-8588?
CVE-2016-8588 is a remote code execution vulnerability due to improper validation of uploaded file names.
5
Can CVE-2016-8588 be exploited remotely?
Yes, CVE-2016-8588 can be exploited remotely by authenticated users.