ZDI-CAN-20181: ZDI-23-591: Trend Micro Mobile Security for Enterprises widgetforsecurity getWidgetPoolManager Local File Inclusion Remote Code Execution Vulnerability
Published May 12, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Mobile Security for Enterprises. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Trend Micro Mobile Security for Enterprises
Event History
May 12, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Aug 2, 2024
Advisory Published
via ZDI·03:25 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is ZDI-CAN-20181.
2
What is the severity of ZDI-CAN-20181?
The severity of ZDI-CAN-20181 is high with a CVSS score of 7.5.
3
What software is affected by ZDI-CAN-20181?
Trend Micro Mobile Security for Enterprises is affected by ZDI-CAN-20181.
4
How can the vulnerability be exploited?
Remote attackers can exploit this vulnerability to execute arbitrary code on affected installations of Trend Micro Mobile Security for Enterprises.
5
Is authentication required to exploit ZDI-CAN-20181?
Yes, authentication is required to exploit ZDI-CAN-20181, but the existing authentication mechanism can be bypassed.