First published: Wed May 03 2017(Updated: )
Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan | =11.0 | |
Trend Micro OfficeScan | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5481 has a medium severity rating as it allows remote authenticated users to gain elevated privileges.
To mitigate CVE-2017-5481, update Trend Micro OfficeScan to version 11.0 SP1 CP 6325 or later, or version 12.0 CP 1352 or later.
CVE-2017-5481 affects users of Trend Micro OfficeScan versions 11.0 before SP1 CP 6325 and 12.0 before CP 1352.
CVE-2017-5481 is a privilege escalation vulnerability that arises from a leak of an encrypted password.
Yes, CVE-2017-5481 can be exploited by remote authenticated users through a web-console operation.