First published: Mon Oct 21 2019(Updated: )
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Anti-threat Toolkit | <=1.62.0.1218 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9491 is classified as a critical vulnerability due to its potential for arbitrary remote code execution.
To mitigate CVE-2019-9491, users should upgrade Trend Micro Anti-Threat Toolkit to version 1.62.0.1219 or later.
CVE-2019-9491 exploits file placement vulnerabilities, allowing attackers to place malicious files in the directory.
Versions of Trend Micro Anti-Threat Toolkit equal to or below 1.62.0.1218 are vulnerable to CVE-2019-9491.
The consequences of CVE-2019-9491 can include remote code execution, which may allow attackers to take control of the affected system.