First published: Tue Aug 01 2017(Updated: )
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Deep Discovery Director | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11381 has been classified with a high severity level due to its potential for unauthorized access and exploitation.
To fix CVE-2017-11381, update Trend Micro Deep Discovery Director to the latest version that addresses the command injection vulnerability.
CVE-2017-11381 specifically affects Trend Micro Deep Discovery Director version 1.1.
An attacker exploiting CVE-2017-11381 can potentially restore accounts that enable access to the pre-configuration console.
There are no officially documented workarounds for CVE-2017-11381, and the best mitigation is to apply the necessary update.