CVE-2003-1341

Trend Micro OfficeScan <3.54, 5.x - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-1341. PoCs published by Rod Boron.

AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in Trend Micro OfficeScan. The vulnerability allows unauthorized access to programs in the cgi directory via a direct URL request.

Description

The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Rod Boron · textremotewindows
https://www.exploit-db.com/exploits/22171

This is a writeup describing an information disclosure vulnerability in Trend Micro OfficeScan. The vulnerability allows unauthorized access to programs in the cgi directory via a direct URL request.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Trend Micro OfficeScan
No auth needed
Prerequisites: Network access to the target OfficeScan server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6181
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/7881
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11059
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6616

Scores

EPSS 0.0766
EPSS Percentile 93.8%

Details

CWE
CWE-16
Status published
Products (9)
trend_micro/officescan 3.0 (2 CPE variants)
trend_micro/officescan 3.1.1
trend_micro/officescan 3.5 (2 CPE variants)
trend_micro/officescan 3.11 (2 CPE variants)
trend_micro/officescan 3.13 (2 CPE variants)
trend_micro/officescan 3.54
trend_micro/virus_buster 3.52
trend_micro/virus_buster 3.53
trend_micro/virus_buster 3.54
Published Dec 31, 2003
Tracked Since Feb 18, 2026