First published: Fri Sep 22 2017(Updated: )
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Mobile Security | =9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14078 has a high severity rating due to the potential for remote code execution.
To fix CVE-2017-14078, upgrade Trend Micro Mobile Security (Enterprise) to version 9.7 Patch 3 or later.
CVE-2017-14078 can facilitate SQL injection attacks allowing attackers to execute arbitrary code.
CVE-2017-14078 affects all versions of Trend Micro Mobile Security (Enterprise) prior to 9.7 Patch 3.
Yes, CVE-2017-14078 can be exploited by remote attackers without requiring authentication.