peter bassill · operator
$ cve CVE-2017-11394 JSON

CVE-2017-11394 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 66.8% (pctl 99)

Patch early

A public exploit exists.

Description

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS66.77% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2017-08-03
Last modified2026-06-17

Affected (1)

VendorProduct
trendmicroofficescan

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD