CVE-2019-18187

CVE Published 2019-10-28
Related CWE(s) CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Related Vendor(s) trendmicro
Related Product(s) officescan
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References