Trend Micro InterScan Messaging Security modTMCSS Command Injection (CVE-2017-11391)

A command injection vulnerability exists in Trend Micro InterScan Messaging Security virtual appliance. The vulnerability is due to improper validation of request parameters within the modTMCSS Proxy functionality. A remote, authenticated attacker could exploit the vulnerability by sending a crafted request to the vulnerable system.

from Check Point Update Services Advisories http://ift.tt/2jres3J

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...