This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Worry-Free Business Security. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web console, which listens on TCP port 4343 by default. The issue results from improper access control. An attacker can leverage this vulnerability to disclose information from the application.
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Apex One and Worry-Free Business Security |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-11765 is considered critical due to the potential for unauthorized information disclosure.
To fix ZDI-CAN-11765, ensure that you update your Trend Micro Worry-Free Business Security to the latest version provided by the vendor.
ZDI-CAN-11765 is classified as an information disclosure vulnerability.
ZDI-CAN-11765 affects installations of Trend Micro Worry-Free Business Security that have not been properly secured.
No, authentication is not required to exploit ZDI-CAN-11765, making it easier for remote attackers.