CVE-2017-11382

HIGH

Trend Micro Deep Discovery Email Inspector 2.5.1 - Denial of Service via Arbitrary File Deletion

Title source: llm
STIX 2.1

Description

Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable installations, thus disabling the service. Formerly ZDI-CAN-4350.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-17-503
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100076
Mitigation, Patch, Vendor Advisory x_refsource_misc
https://success.trendmicro.com/solution/1116750

Scores

CVSS v3 7.5
EPSS 0.0112
EPSS Percentile 78.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-668
Status published
Products (2)
Trend Micro/Trend Micro Deep Discovery Email Inspector 2.5.1
trendmicro/deep_discovery_email_inspector 2.5.1
Published Aug 03, 2017
Tracked Since Feb 18, 2026