Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-3987. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages an arbitrary command execution vulnerability in Trend Micro Maximum Security 10's Password Manager component via an exposed HTTP RPC endpoint. It uses JavaScript to send a crafted request to the local API, bypassing same-origin policy to execute commands via `ShellExecute()`.
Description
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
Exploits (1)
This exploit leverages an arbitrary command execution vulnerability in Trend Micro Maximum Security 10's Password Manager component via an exposed HTTP RPC endpoint. It uses JavaScript to send a crafted request to the local API, bypassing same-origin policy to execute commands via `ShellExecute()`.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H