CVE-2018-3606: Trend Micro Control Manager PersonalFirewallSummary SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Control Manager. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AntiVirusSummary method, which is called by the reporting servlet. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code under the context of the Network Service account.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Control Manager. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ApplicationCompliance method, which is called by the reporting servlet. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code under the context of the Network Service account.
— ZDI
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Control Manager. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ApplicationStatus method, which is called by the reporting servlet. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code under the context of the Network Service account.
— ZDI
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Control Manager. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ComponentCompliance method, which is called by the reporting servlet. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code under the context of the Network Service account.
— ZDI
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Control Manager. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ContentSecuritySummary method, which is called by the reporting servlet. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code under the context of the Network Service account.
— ZDI
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Control Manager. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the NetworkVirusSummary method, which is called by the reporting servlet. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code under the context of the Network Service account.
— ZDI
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-3606?
CVE-2018-3606 is a vulnerability that allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Control Manager.
How does CVE-2018-3606 work?
CVE-2018-3606 exploits an SQL injection vulnerability in Trend Micro Control Manager, allowing attackers to bypass authentication and execute arbitrary code.
What is the severity of CVE-2018-3606?
CVE-2018-3606 has a severity rating of 8.8 (high).
What software is affected by CVE-2018-3606?
CVE-2018-3606 affects installations of Trend Micro Control Manager version 6.0.
How can I fix CVE-2018-3606?
To fix CVE-2018-3606, it is recommended to upgrade to a non-vulnerable version of Trend Micro Control Manager.