CVE-2018-10351: Trend Micro Encryption for Email Gateway register2 Client SQL Injection Remote Code Execution Vulnerability
A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRegistration2 class. Authentication is required to exploit this vulnerability.
Other sources
This vulnerability allows remote attackers to execute arbitrary SQL statements on vulnerable installations of Trend Micro Encryption for Email Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the formRegistration2 class. A crafted Client field in ppreg files can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this vulnerability to execute code under the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10351?
CVE-2018-10351 is considered to have a high severity due to its potential for remote code execution.
How do I fix CVE-2018-10351?
To mitigate CVE-2018-10351, update the Trend Micro Email Encryption Gateway to the latest version that addresses this vulnerability.
What is affected by CVE-2018-10351?
CVE-2018-10351 affects Trend Micro Email Encryption Gateway version 5.5 and earlier installations.
What type of attack can exploit CVE-2018-10351?
CVE-2018-10351 can be exploited through a remote attack allowing the execution of arbitrary SQL statements.
Is authentication required to exploit CVE-2018-10351?
Yes, authentication is required to exploit CVE-2018-10351.