ZDI-23-591: Trend Micro Mobile Security for Enterprises widgetforsecurity getWidgetPoolManager Local File Inclusion Remote Code Execution Vulnerability
Published May 12, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Mobile Security for Enterprises. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Trend Micro Mobile Security for Enterprises
Event History
May 12, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Aug 2, 2024
Advisory Published
via ZDI·03:25 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is ZDI-23-591.
2
What software is affected by this vulnerability?
This vulnerability affects Trend Micro Mobile Security for Enterprises.
3
What is the severity level of ZDI-23-591?
The severity level of ZDI-23-591 is high.
4
How can this vulnerability be exploited?
Remote attackers can execute arbitrary code on affected installations of Trend Micro Mobile Security for Enterprises by bypassing the existing authentication mechanism.
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to follow the guidance provided by Trend Micro at [insert reference link here].