ZDI-CAN-20182: ZDI-23-586: Trend Micro Mobile Security for Enterprises widgetforsecurity set_certificates_config Unrestricted File Upload Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Trend Micro Mobile Security for Enterprises. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20182?
The severity of ZDI-CAN-20182 is considered high due to the ability of remote attackers to create arbitrary files.
How do I fix ZDI-CAN-20182?
To fix ZDI-CAN-20182, update to the latest version of Trend Micro Mobile Security for Enterprises that addresses this vulnerability.
What types of attacks are possible with ZDI-CAN-20182?
ZDI-CAN-20182 allows remote attackers to exploit the vulnerability to create arbitrary files, potentially leading to further exploitation.
Who is affected by ZDI-CAN-20182?
Organizations using Trend Micro Mobile Security for Enterprises are affected by ZDI-CAN-20182.
Is authentication required to exploit ZDI-CAN-20182?
Yes, authentication is required to exploit ZDI-CAN-20182, but the existing mechanism can be bypassed.