CVE-2003-1341 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.7% (pctl 94)
Patch early
A public exploit exists.
Description
The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.66% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-16 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| trend micro | officescan |
| trend micro | virus buster |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Trend Micro OfficeScan 3.x - CGI Directory Insufficient Permissions | 2003-01-15 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html
- http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353
- http://secunia.com/advisories/7881
- http://www.osvdb.org/6181
- http://www.securityfocus.com/bid/6616
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11059
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html
- http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353
- http://secunia.com/advisories/7881
- http://www.osvdb.org/6181
- http://www.securityfocus.com/bid/6616
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11059
→ the Explorer · watch your stack · NVD