ZDI-CAN-11569: Trend Micro ServerProtect vsapiapp Memory Exhaustion Denial-Of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Trend Micro ServerProtect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the vsapiapp executable. The issue results from the lack of proper validation of user-supplied data, which can result in a memory exhaustion condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-11569?
ZDI-CAN-11569 has been classified as a denial-of-service vulnerability.
How do I fix ZDI-CAN-11569?
To mitigate ZDI-CAN-11569, ensure you have the latest updates from Trend Micro for ServerProtect.
What types of attacks can exploit ZDI-CAN-11569?
ZDI-CAN-11569 can be exploited remotely through malicious pages or files that require user interaction.
Which versions of Trend Micro ServerProtect are affected by ZDI-CAN-11569?
ZDI-CAN-11569 affects specific installations of Trend Micro ServerProtect, particularly those not updated to the latest versions.
Is user interaction required for the exploitation of ZDI-CAN-11569?
Yes, user interaction is required for the exploitation of ZDI-CAN-11569, as the target must visit a malicious page or open a malicious file.