First published: Thu Oct 05 2017(Updated: )
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan | =11.0 | |
Trend Micro OfficeScan | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14087 is considered to have a medium severity level due to its potential impact on the confidentiality and integrity of user interactions.
To fix CVE-2017-14087, it is recommended to upgrade to the latest version of Trend Micro OfficeScan that addresses this vulnerability.
CVE-2017-14087 affects Trend Micro OfficeScan versions 11.0 and 12.0.
A Host Header Injection vulnerability allows an attacker to manipulate the Host header in HTTP requests, potentially redirecting users to malicious sites.
Yes, exploitation of CVE-2017-14087 could result in data breaches if users are redirected to malicious websites.