CVE-2017-11398 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 8.2% (pctl 95)
Patch early
A public exploit exists.
Description
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 8.2% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-285 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-01-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| trendmicro | smart protection server |
Public exploits
References
- http://www.securityfocus.com/bid/102275
- https://success.trendmicro.com/solution/1118992
- https://www.coresecurity.com/advisories/trend-micro-smart-protection-server-multiple-vulnerabilities
- https://www.exploit-db.com/exploits/43388/
- http://www.securityfocus.com/bid/102275
- https://success.trendmicro.com/solution/1118992
- https://www.coresecurity.com/advisories/trend-micro-smart-protection-server-multiple-vulnerabilities
- https://www.exploit-db.com/exploits/43388/
→ the Explorer · watch your stack · NVD