CVE-2017-14089

critical

Description

An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.

References

https://success.trendmicro.com/solution/1118372

http://www.securitytracker.com/id/1039500

http://www.securityfocus.com/bid/101076

http://www.securityfocus.com/archive/1/541271/100/0/threaded

http://seclists.org/fulldisclosure/2017/Sep/91

Details

Source: Mitre, NVD

Published: 2017-10-06

Updated: 2018-10-09

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical