CVE-2017-11392
HIGHTrendmicro Interscan Messaging Securi... - Command Injection
Title source: ruleDescription
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/trendmicro_imsva_widget_exec.rb
Scores
CVSS v3
8.8
EPSS
0.7393
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (3)
Trend Micro/Trend Micro InterScan Messaging Security Virtual Appliance
9.0,9.1
trendmicro/interscan_messaging_security_virtual_appliance
9.0
trendmicro/interscan_messaging_security_virtual_appliance
9.1
Published
Aug 03, 2017
Tracked Since
Feb 18, 2026