CVE-2018-6231: Trend Micro Smart Protection Server Auth Command Injection Authentication Bypass Vulnerability
Published Mar 15, 2018
·Updated
A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vulnerable installations.
Affected Software
1 affected component
trendmicro Smart Protection Server<=3.3
Event History
Mar 15, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Jun 29, 2026
Advisory Published
via ZDI·02:41 AM
Data Sourced
via ZDI·02:41 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6231?
CVE-2018-6231 is classified as a critical severity vulnerability that allows for remote privilege escalation.
2
How do I fix CVE-2018-6231?
To remediate CVE-2018-6231, update Trend Micro Smart Protection Server to version 3.4 or higher.
3
What products are affected by CVE-2018-6231?
CVE-2018-6231 affects Trend Micro Smart Protection Server versions 3.3 and below.
4
Can CVE-2018-6231 be exploited remotely?
Yes, CVE-2018-6231 can be exploited remotely by attackers due to the server auth command injection flaw.
5
What kind of attacks can CVE-2018-6231 facilitate?
CVE-2018-6231 can facilitate privilege escalation attacks, allowing unauthorized access to vulnerable installations.