CVE-2017-14096
CVE-2017-14096
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 3.1%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
19 Dec 2017Public PoC
19 Jan 2018Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload on vulnerable systems.
Affected products
Trend Micro · Trend Micro Smart Protection Server (Standalone)public PoCs found — 2
cve_referencewww.exploit-db.com/exploits/43388/unverifiedexploitdbwww.exploit-db.com/exploits/43388unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →