ZDI-CAN-5640: Trend Micro Endpoint Application Control FileDrop Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Endpoint Application Control. Authentication is required to exploit this vulnerability. The specific flaw exists within the FileDrop servlet. When parsing filenames, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code under the context of administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-5640?
The severity of ZDI-CAN-5640 is high due to its potential for remote code execution.
How do I fix ZDI-CAN-5640?
To fix ZDI-CAN-5640, ensure you update your Trend Micro Endpoint Application Control to the latest version.
What software does ZDI-CAN-5640 affect?
ZDI-CAN-5640 affects Trend Micro Endpoint Application Control installations.
Is authentication required to exploit ZDI-CAN-5640?
Yes, authentication is required to exploit the ZDI-CAN-5640 vulnerability.
What specific component is vulnerable in ZDI-CAN-5640?
The specific component vulnerable in ZDI-CAN-5640 is the FileDrop servlet that handles filename parsing.