CVE-2018-6222: OS Command Injection
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6222?
CVE-2018-6222 is considered a critical vulnerability due to its potential to allow arbitrary command execution.
How do I fix CVE-2018-6222?
To address CVE-2018-6222, it is recommended to upgrade Trend Micro Email Encryption Gateway to a patched version beyond 5.5.
What type of attack does CVE-2018-6222 facilitate?
CVE-2018-6222 can facilitate command execution on a vulnerable system by exploiting arbitrary log file locations.
Which software versions are affected by CVE-2018-6222?
CVE-2018-6222 specifically affects Trend Micro Email Encryption Gateway version 5.5.
Is CVE-2018-6222 easy to exploit?
CVE-2018-6222 can be exploited with relative ease if proper security measures are not in place.