ZDI-23-589: Trend Micro Mobile Security for Enterprises widget set_certificates_config Unrestricted File Upload Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Trend Micro Mobile Security for Enterprises. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is ZDI-23-589.
What is the severity level of ZDI-23-589?
The severity level of ZDI-23-589 is medium with a severity value of 6.5.
What software is affected by ZDI-23-589?
ZDI-23-589 affects Trend Micro Mobile Security for Enterprises.
How can this vulnerability be exploited?
Remote attackers can exploit this vulnerability by creating arbitrary files on affected installations of Trend Micro Mobile Security for Enterprises, bypassing the existing authentication mechanism.
Is there any fix or solution available for ZDI-23-589?
Yes, there is a solution available for ZDI-23-589. It is recommended to refer to the Trend Micro solution (https://success.trendmicro.com/solution/000293106) for the fix or mitigation steps.