Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14089. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a remote memory corruption vulnerability in TrendMicro OfficeScan XG by sending a maliciously crafted cookie to the cgiShowClientAdm.exe endpoint. The payload consists of an overly long 'LogonUser' cookie value, which triggers the memory corruption.
Description
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.
Exploits (1)
This exploit demonstrates a remote memory corruption vulnerability in TrendMicro OfficeScan XG by sending a maliciously crafted cookie to the cgiShowClientAdm.exe endpoint. The payload consists of an overly long 'LogonUser' cookie value, which triggers the memory corruption.
References (8)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H