CVE-2020-27017: XEE
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27017?
CVE-2020-27017 is a vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 that allows an authenticated administrator to read arbitrary local files.
How severe is CVE-2020-27017?
CVE-2020-27017 has a severity rating of 4.9, which is considered medium.
How can an attacker exploit CVE-2020-27017?
To exploit CVE-2020-27017, an attacker must have obtained product administrator/root privileges and can then use an XML External Entity Processing (XXE) vulnerability to read arbitrary local files.
Is Windows affected by CVE-2020-27017?
No, Microsoft Windows is not affected by CVE-2020-27017.
Where can I find more information about CVE-2020-27017?
You can find more information about CVE-2020-27017 at the following references: 1. https://sec-consult.com/en/blog/advisories/vulnerabilities-in-trend-micro-interscan-messaging-security-virtual-appliance-imsva/ 2. https://success.trendmicro.com/solution/000279833