ZDI-20-676: Trend Micro InterScan Web Security Virtual Appliance Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro InterScan Web Security Virtual Appliance. Authentication is required to exploit this vulnerability. The specific flaw exists within the LogSettingHandler class. When parsing the mountdevice parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-20-676?
The severity of ZDI-20-676 is high due to its potential for remote code execution.
How do I fix ZDI-20-676?
To fix ZDI-20-676, update your Trend Micro InterScan Web Security Virtual Appliance to the latest version provided by Trend Micro.
What systems are affected by ZDI-20-676?
ZDI-20-676 affects installations of Trend Micro InterScan Web Security Virtual Appliance.
Does ZDI-20-676 require authentication to exploit?
Yes, ZDI-20-676 requires authentication to exploit the vulnerability.
What type of vulnerability is ZDI-20-676?
ZDI-20-676 is a remote code execution vulnerability.