CVE-2018-10356: Trend Micro Encryption for Email Gateway requestDomains hidDomains SQL Injection Remote Code Execution Vulnerability
A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRequestDomains class. Authentication is required to exploit this vulnerability.
Other sources
This vulnerability allows remote attackers to execute arbitrary SQL statements on vulnerable installations of Trend Micro Encryption for Email Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the formRequestDomains class. When parsing the hidDomains parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10356?
CVE-2018-10356 is a critical severity vulnerability that allows for remote code execution due to SQL injection.
How do I fix CVE-2018-10356?
To fix CVE-2018-10356, update Trend Micro Email Encryption Gateway to the latest patch provided by Trend Micro.
Who can exploit CVE-2018-10356?
CVE-2018-10356 can be exploited by authenticated users who have access to the vulnerable installations.
What impact does CVE-2018-10356 have on systems?
CVE-2018-10356 can lead to unauthorized execution of arbitrary SQL statements, potentially compromising the database.
Which versions of Trend Micro Email Encryption Gateway are affected by CVE-2018-10356?
Versions of Trend Micro Email Encryption Gateway up to 5.5 are affected by CVE-2018-10356.