← back
CVE-2017-11391

CVE-2017-11391

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 62%
from disclosure to weapon65 days
Published on NVDAug 3
metasploit+65d
exploitation probability
62%top 1% of all CVEs
observed exploitation
nono source reports it
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4744.