ZDI-CAN-20180: ZDI-23-590: Trend Micro Mobile Security for Enterprises widget getWidgetPoolManager Local File Inclusion Remote Code Execution Vulnerability
Published May 12, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Mobile Security for Enterprises. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Trend Micro Mobile Security for Enterprises
Event History
May 12, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Aug 2, 2024
Advisory Published
via ZDI·03:25 PM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20180?
ZDI-CAN-20180 has a high severity rating due to the ability for remote attackers to execute arbitrary code.
2
How do I fix ZDI-CAN-20180?
To fix ZDI-CAN-20180, apply the latest security updates provided by Trend Micro for Mobile Security for Enterprises.
3
What software is affected by ZDI-CAN-20180?
ZDI-CAN-20180 affects Trend Micro Mobile Security for Enterprises.
4
Can ZDI-CAN-20180 be exploited without authentication?
No, ZDI-CAN-20180 requires authentication; however, the existing authentication can be bypassed.
5
What type of attack does ZDI-CAN-20180 allow?
ZDI-CAN-20180 allows remote attackers to execute arbitrary code on the affected installations.