CVE-2018-3601: Trend Micro Control Manager TMCM_MembershipProvider ValidateUser Password Hash Usage Authentication Bypass Vulnerability
A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on vulnerable installations.
Other sources
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Trend Micro Control Manager. User interaction is not required to exploit this vulnerability. The specific flaw exists within the handling of challenges for authentication. The implementation of the challenge allows an attacker to authenticate to the system if they have possession of the password hash but not the password for a user. An attacker can leverage this vulnerability in conjunction with other vulnerabilities to bypass authentication.
— ZDI
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-3601?
CVE-2018-3601 is a vulnerability that allows remote attackers to bypass authentication on vulnerable installations of Trend Micro Control Manager.
How does CVE-2018-3601 work?
CVE-2018-3601 exists within the handling of challenges for authentication in Trend Micro Control Manager, allowing attackers to bypass authentication.
Is user interaction required to exploit CVE-2018-3601?
No, user interaction is not required to exploit CVE-2018-3601.
Which versions of Trend Micro Control Manager are affected by CVE-2018-3601?
Trend Micro Control Manager version 6.0 is affected by CVE-2018-3601.
How can I fix CVE-2018-3601?
To fix CVE-2018-3601, it is recommended to update to a patched version of Trend Micro Control Manager.