CVE-2017-14095: High severity trend micro smart protection server vulnerability
Published Jan 19, 2018
·Updated
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system.
Affected Software
1 affected component
trendmicro Smart Protection Server<=3.2
Event History
Jan 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14095?
CVE-2017-14095 is classified as a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2017-14095?
To fix CVE-2017-14095, users should upgrade to Trend Micro Smart Protection Server version 3.3 or higher.
3
What kind of attack can exploit CVE-2017-14095?
CVE-2017-14095 can be exploited through local file inclusion which may lead to remote command execution.
4
What versions of Trend Micro Smart Protection Server are affected by CVE-2017-14095?
CVE-2017-14095 affects all versions of Trend Micro Smart Protection Server up to and including 3.2.
5
Is CVE-2017-14095 a zero-day vulnerability?
CVE-2017-14095 is not a zero-day vulnerability as it was publicly disclosed, allowing time for users to patch their systems.