CVE-2017-14087: Input Validation
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14087?
CVE-2017-14087 is considered to have a medium severity level due to its potential impact on the confidentiality and integrity of user interactions.
How do I fix CVE-2017-14087?
To fix CVE-2017-14087, it is recommended to upgrade to the latest version of Trend Micro OfficeScan that addresses this vulnerability.
What versions of Trend Micro OfficeScan are affected by CVE-2017-14087?
CVE-2017-14087 affects Trend Micro OfficeScan versions 11.0 and 12.0.
What is a Host Header Injection vulnerability as seen in CVE-2017-14087?
A Host Header Injection vulnerability allows an attacker to manipulate the Host header in HTTP requests, potentially redirecting users to malicious sites.
Is there a risk of data breach with CVE-2017-14087?
Yes, exploitation of CVE-2017-14087 could result in data breaches if users are redirected to malicious websites.