CVE-2017-11392: Command Injection
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11392?
CVE-2017-11392 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2017-11392?
To mitigate CVE-2017-11392, upgrade to a patched version of Trend Micro InterScan Messaging Virtual Appliance that addresses this vulnerability.
What software versions are affected by CVE-2017-11392?
CVE-2017-11392 affects Trend Micro InterScan Messaging Virtual Appliance versions 9.0 and 9.1.
Can CVE-2017-11392 be exploited remotely?
Yes, CVE-2017-11392 can be exploited remotely, allowing attackers to execute arbitrary code.
What type of vulnerability is CVE-2017-11392?
CVE-2017-11392 is classified as a proxy command injection vulnerability.