Vulnerabilities > CVE-2017-9036 - Missing Authorization vulnerability in Trendmicro Serverprotect 3.0

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
trendmicro
CWE-862

Summary

Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.

Vulnerable Configurations

Part Description Count
Application
Trendmicro
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/142645/CORE-2017-0002.txt
idPACKETSTORM:142645
last seen2017-05-25
published2017-05-24
reporterAlberto Solino
sourcehttps://packetstormsecurity.com/files/142645/Trend-Micro-ServerProtect-Disclosure-CSRF-XSS.html
titleTrend Micro ServerProtect Disclosure / CSRF / XSS