First published: Mon Nov 09 2020(Updated: )
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Interscan Messaging Security Virtual Appliance | <=9.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27017 is a vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 that allows an authenticated administrator to read arbitrary local files.
CVE-2020-27017 has a severity rating of 4.9, which is considered medium.
To exploit CVE-2020-27017, an attacker must have obtained product administrator/root privileges and can then use an XML External Entity Processing (XXE) vulnerability to read arbitrary local files.
No, Microsoft Windows is not affected by CVE-2020-27017.
You can find more information about CVE-2020-27017 at the following references: 1. https://sec-consult.com/en/blog/advisories/vulnerabilities-in-trend-micro-interscan-messaging-security-virtual-appliance-imsva/ 2. https://success.trendmicro.com/solution/000279833