vendor:
OfficeScan XG
by:
John Page (aka hyp3rlinx)
7,5
CVSS
HIGH
Unauthorized Start Remote Process Code Execution & Unauthorized Denial Of Service - INI Corruption
284
CWE
Product Name: OfficeScan XG
Affected Version From: v11.0
Affected Version To: v12.0
Patch Exists: YES
Related CWE: CVE-2017-14086
CPE: a:trend_micro:officescan_xg
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Unauthorized Start Remote Process Code Execution
Remote unauthenticated attackers who connect to the OfficeScan XG application can temporarily start the "fcgiOfcDDA.exe" executable this process will run for short time before dies, server disk space may also be consumed with dump files by making continous HTTP requests.
Mitigation:
Update to the latest version of OfficeScan XG