CVE-2017-14095
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 12%
from disclosure to weapon0 days
Published on NVDJan 19
1st PoCDec 19
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short
Trend Micro Smart Protection Server versions 3.2 and below have a flaw that allows attackers to run commands remotely on the affected system by exploiting a file inclusion weakness. This can give an attacker full control over the server.
Technical detail
A local file inclusion (LFI) vulnerability in Trend Micro Smart Protection Server ≤3.2 enables remote command execution (RCE) when an attacker manipulates file paths to include and execute malicious code. The attack requires network access to the vulnerable application endpoint.
Summary generated and translated by AI from the official description.
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system.
Affected products
Trend Micro · Trend Micro Smart Protection Server (Standalone)public PoCs found — 2
exploitdbwww.exploit-db.com/exploits/43388unverifiedcve_referencewww.exploit-db.com/exploits/43388/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.