ZDI-CAN-20179: ZDI-23-589: Trend Micro Mobile Security for Enterprises widget set_certificates_config Unrestricted File Upload Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Trend Micro Mobile Security for Enterprises. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is ZDI-CAN-20179.
What is the severity of the ZDI-CAN-20179 vulnerability?
The severity of the ZDI-CAN-20179 vulnerability is medium (6.5).
What is the affected software for this vulnerability?
The affected software for this vulnerability is Trend Micro Mobile Security for Enterprises.
How can remote attackers exploit the ZDI-CAN-20179 vulnerability?
Remote attackers can exploit the ZDI-CAN-20179 vulnerability by creating arbitrary files on affected installations of Trend Micro Mobile Security for Enterprises, bypassing the authentication mechanism.
Where can I find more information about the ZDI-CAN-20179 vulnerability?
You can find more information about the ZDI-CAN-20179 vulnerability at the following references: [1] http://www.zerodayinitiative.com/advisories/ZDI-23-589/ [2] https://success.trendmicro.com/solution/000293106 [3] https://www.zerodayinitiative.com/advisories/ZDI-23-589/