First published: Fri Feb 09 2018(Updated: )
An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Control Manager | =6.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-3602 is high with a severity value of 8.8.
Remote attackers can exploit CVE-2018-3602 by executing arbitrary code on vulnerable installations of Trend Micro Control Manager.
Yes, authentication is required to exploit CVE-2018-3602. However, the existing authentication mechanism can be bypassed.
Trend Micro Control Manager version 6.0 is affected by CVE-2018-3602.
To fix CVE-2018-3602, update Trend Micro Control Manager to a patched version provided by the vendor.