CVE-2017-14094: OS Command Injection
Published Jan 19, 2018
·Updated
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.
Affected Software
1 affected component
trendmicro Smart Protection Server<=3.2
Event History
Jan 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14094?
CVE-2017-14094 is rated as a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2017-14094?
To remediate CVE-2017-14094, upgrade Trend Micro Smart Protection Server to version 3.3 or later.
3
Which versions are affected by CVE-2017-14094?
CVE-2017-14094 affects Trend Micro Smart Protection Server versions 3.2 and below.
4
What type of attack does CVE-2017-14094 facilitate?
CVE-2017-14094 allows attackers to perform remote command execution via cron job injection.
5
Who is at risk from CVE-2017-14094?
Organizations using Trend Micro Smart Protection Server versions 3.2 and below are at risk from CVE-2017-14094.