CVE-2016-9269: Critical severity trendmicro Interscan Web Security Virtual Appliance vulnerability
Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2BuildLinux1707 and earlier allows authenticated, remote users with least privileges to run arbitrary commands on the system as root via Patch Update functionality. This was resolved in Version 6.5 CP 1737.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9269?
CVE-2016-9269 is classified as a critical vulnerability due to its ability to allow remote command execution.
How do I fix CVE-2016-9269?
To remediate CVE-2016-9269, update Trend Micro Interscan Web Security Virtual Appliance to version 6.5-SP2_Build_Linux_1708 or later.
Who is affected by CVE-2016-9269?
CVE-2016-9269 affects authenticated remote users with least privileges on Trend Micro Interscan Web Security Virtual Appliance versions 6.5-SP2_Build_Linux_1707 and earlier.
What systems are vulnerable to CVE-2016-9269?
Systems running Trend Micro Interscan Web Security Virtual Appliance versions up to 6.5-SP2_Build_Linux_1707 are vulnerable to CVE-2016-9269.
What can attackers do with CVE-2016-9269?
Attackers exploiting CVE-2016-9269 can execute arbitrary commands on the affected system as root.