CVE-2017-14089

CRITICAL

Trend Micro OfficeScan <11.0 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-14089. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit demonstrates a remote memory corruption vulnerability in TrendMicro OfficeScan XG by sending a maliciously crafted cookie to the cgiShowClientAdm.exe endpoint. The payload consists of an overly long 'LogonUser' cookie value, which triggers the memory corruption.

Description

An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · pythondoswindows
https://www.exploit-db.com/exploits/42920

This exploit demonstrates a remote memory corruption vulnerability in TrendMicro OfficeScan XG by sending a maliciously crafted cookie to the cgiShowClientAdm.exe endpoint. The payload consists of an overly long 'LogonUser' cookie value, which triggers the memory corruption.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: TrendMicro OfficeScan v11.0 and XG (12.0)
No auth needed
Prerequisites: Network access to the target's OfficeScan server on port 4343
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Patch, Vendor Advisory x_refsource_confirm
https://success.trendmicro.com/solution/1118372
Mailing List, Third Party Advisory, VDB Entry mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/Sep/91
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42920/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/541271/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039500
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101076

Scores

CVSS v3 9.8
EPSS 0.0978
EPSS Percentile 94.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (3)
Trend Micro/Trend Micro OfficeScan 11.0, XG (12.0)
trendmicro/officescan 11.0 sp1
trendmicro/officescan 12.0
Published Oct 06, 2017
Tracked Since Feb 18, 2026