CVE-2019-9491

HIGH

Trend Micro ATTK <1.62.0.1218 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-9491. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit leverages a vulnerability in Trend Micro Anti-Threat Toolkit (ATTK) where arbitrary .EXE files named 'cmd.exe' or 'regedit.exe' are executed during a scan. The provided C code compiles into a malicious executable that launches PowerShell when executed by the ATTK.

Description

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hyp3rlinx · textlocalwindows
https://www.exploit-db.com/exploits/47527

This exploit leverages a vulnerability in Trend Micro Anti-Threat Toolkit (ATTK) where arbitrary .EXE files named 'cmd.exe' or 'regedit.exe' are executed during a scan. The provided C code compiles into a malicious executable that launches PowerShell when executed by the ATTK.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Trend Micro Anti-Threat Toolkit (ATTK) 1.62.0.1218 and below
No auth needed
Prerequisites: Ability to place a malicious executable named 'cmd.exe' or 'regedit.exe' in a directory scanned by ATTK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Vendor Advisory x_refsource_misc
https://success.trendmicro.com/solution/000149878
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Oct/30
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Oct/42
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2020/Jan/55
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Jan/50

Scores

CVSS v3 7.8
EPSS 0.1294
EPSS Percentile 95.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
trendmicro/anti-threat_toolkit < 1.62.0.1218
Published Oct 21, 2019
Tracked Since Feb 18, 2026