← back
CVE-2017-11394

CVE-2017-11394

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 67%
from disclosure to weapon69 days
Published on NVDAug 3
1st PoC+69d
metasploit+65d
exploitation probability
67%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.