CVE-2019-18187: Trend Micro OfficeScan Directory Traversal Vulnerability
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.
Other sources
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure the web service account used by the remote process execution (for the web platform in use) has restricted permissions to limit impact if remote code execution occurs.
- Compensating control
Apply authentication controls to any functionality exposed over the web that could be abused for remote process execution, since the attempted attack requires user authentication.
Event History
Frequently Asked Questions
What is CVE-2019-18187?
CVE-2019-18187 is a directory traversal vulnerability in Trend Micro OfficeScan that could potentially lead to remote code execution (RCE).
Which versions of Trend Micro OfficeScan are affected by CVE-2019-18187?
Trend Micro OfficeScan versions 11.0 and XG (12.0) are affected by CVE-2019-18187.
How can an attacker exploit CVE-2019-18187?
An attacker can exploit CVE-2019-18187 by utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server.
What is the severity of CVE-2019-18187?
CVE-2019-18187 has a severity rating of 7.5 (High).
How can I fix CVE-2019-18187?
To fix CVE-2019-18187, it is recommended to update to a patched version of Trend Micro OfficeScan.