보안뉴스 아카이브
긴급도 73/100 심각도 7.5 · 높음 악용확률 97.8% CISA KEV · 2021-11-03 CWE-22

CVE-2019-18187

CISA 기관 조치 기한: 2022-05-03

Trend Micro OfficeScan

Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.
KEV 필수 조치: Apply updates per vendor instructions.

벡터: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

NVD 상세 ↗   벤더 권고문 ↗   참고 링크 ↗

← 취약점 목록