CVE-2018-6222

HIGH

Trendmicro Email Encryption Gateway - OS Command Injection

Title source: rule

Description

Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Core Security · textwebappsjsp
https://www.exploit-db.com/exploits/44166

Scores

CVSS v3 7.8
EPSS 0.0040
EPSS Percentile 60.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-78
Status published

Affected Products (1)

trendmicro/email_encryption_gateway

Timeline

Published Mar 15, 2018
Tracked Since Feb 18, 2026