peter bassill · operator
$ cve CVE-2018-6220 JSON

CVE-2018-6220 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 9.9% (pctl 95)

Patch early

A public exploit exists.

Description

An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.85% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploityes
Published2018-03-15
Last modified2026-06-17

Affected (1)

VendorProduct
trendmicroemail encryption gateway

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD