CVE-2017-11397: High severity trendmicro Encryption For Email vulnerability
Published Dec 15, 2017
·Updated
A service DLL preloading vulnerability in Trend Micro Encryption for Email versions 5.6 and below could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable system.
Affected Software
1 affected component
trendmicro Encryption For Email<=5.6.0.1073
Remediation
Patch Available
Event History
Dec 15, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11397?
CVE-2017-11397 has a high severity rating due to the potential for remote code execution by unauthenticated attackers.
2
How do I fix CVE-2017-11397?
To fix CVE-2017-11397, upgrade Trend Micro Encryption for Email to version 5.7 or later.
3
Who is affected by CVE-2017-11397?
CVE-2017-11397 affects users of Trend Micro Encryption for Email versions 5.6 and below.
4
What type of vulnerability is CVE-2017-11397?
CVE-2017-11397 is classified as a service DLL preloading vulnerability.
5
Can CVE-2017-11397 be exploited remotely?
Yes, CVE-2017-11397 can be exploited by unauthenticated remote attackers to execute arbitrary code.