CVE-2017-14085 EXPLOIT
5.3
MEDIUM · CVSS 3.0 · EPSS 5.7% (pctl 93)
Patch early
A public exploit exists.
Description
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.
Scoring
| CVSS | 5.3 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 5.65% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-10-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| trendmicro | officescan |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Trend Micro OfficeScan 11.0/XG (12.0) - Information Disclosure | 2017-09-28 |
References
- http://hyp3rlinx.altervista.org/advisories/CVE-2017-14085-TRENDMICRO-OFFICESCAN-XG-REMOTE-NT-DOMAIN-PHP-INFO-DISCLOSURE.txt
- http://packetstormsecurity.com/files/144402/TrendMicro-OfficeScan-11.0-XG-12.0-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2017/Sep/85
- http://www.securityfocus.com/archive/1/541281/100/0/threaded
- http://www.securityfocus.com/bid/101076
- http://www.securitytracker.com/id/1039500
- https://success.trendmicro.com/solution/1118372
- https://www.exploit-db.com/exploits/42893/
- http://hyp3rlinx.altervista.org/advisories/CVE-2017-14085-TRENDMICRO-OFFICESCAN-XG-REMOTE-NT-DOMAIN-PHP-INFO-DISCLOSURE.txt
- http://packetstormsecurity.com/files/144402/TrendMicro-OfficeScan-11.0-XG-12.0-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2017/Sep/85
- http://www.securityfocus.com/archive/1/541281/100/0/threaded
- http://www.securityfocus.com/bid/101076
- http://www.securitytracker.com/id/1039500
- https://success.trendmicro.com/solution/1118372
- https://www.exploit-db.com/exploits/42893/
→ the Explorer · watch your stack · NVD