CVE-2017-11385: SQL Injection
Published Aug 2, 2017
·Updated
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-4545.
Affected Software
1 affected component
trendmicro Control Manager=6.0
Remediation
Patch Available
Event History
Aug 2, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11385?
CVE-2017-11385 is rated as critical due to its potential for remote code execution resulting from SQL injection vulnerabilities.
2
How do I fix CVE-2017-11385?
To fix CVE-2017-11385, it is recommended to update the Trend Micro Control Manager to the latest version that addresses this vulnerability.
3
What software is affected by CVE-2017-11385?
CVE-2017-11385 specifically affects Trend Micro Control Manager version 6.0.
4
What type of vulnerability is CVE-2017-11385?
CVE-2017-11385 is an SQL injection vulnerability that can lead to remote code execution.
5
Is CVE-2017-11385 easily exploitable?
Yes, CVE-2017-11385 is considered to be easily exploitable due to insufficient input validation.