Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14086. PoCs published by hyp3rlinx.
AI-analyzed exploit summary The exploit demonstrates unauthenticated remote process execution and denial-of-service via direct HTTP requests to vulnerable Trend Micro OfficeScan XG endpoints. It triggers the execution of 'fcgiOfcDDA.exe' and causes INI corruption via 'cgiRqUpd.exe'.
Description
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause the server disk space to be consumed with dump files from continuous HTTP requests.
Exploits (1)
The exploit demonstrates unauthenticated remote process execution and denial-of-service via direct HTTP requests to vulnerable Trend Micro OfficeScan XG endpoints. It triggers the execution of 'fcgiOfcDDA.exe' and causes INI corruption via 'cgiRqUpd.exe'.
References (8)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H