CVE-2017-5481: Infoleak
Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5481?
CVE-2017-5481 has a medium severity rating as it allows remote authenticated users to gain elevated privileges.
How do I fix CVE-2017-5481?
To mitigate CVE-2017-5481, update Trend Micro OfficeScan to version 11.0 SP1 CP 6325 or later, or version 12.0 CP 1352 or later.
Who is affected by CVE-2017-5481?
CVE-2017-5481 affects users of Trend Micro OfficeScan versions 11.0 before SP1 CP 6325 and 12.0 before CP 1352.
What type of vulnerability is CVE-2017-5481?
CVE-2017-5481 is a privilege escalation vulnerability that arises from a leak of an encrypted password.
Can CVE-2017-5481 be exploited remotely?
Yes, CVE-2017-5481 can be exploited by remote authenticated users through a web-console operation.