cve/2017/CVE-2017-14089.md

21 lines
1019 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2017-14089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14089)
![](https://img.shields.io/static/v1?label=Product&message=Trend%20Micro%20OfficeScan&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Unauthorized%20Memory%20Corruption&color=brighgreen)
### Description
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.
### POC
#### Reference
- http://hyp3rlinx.altervista.org/advisories/CVE-2017-14089-TRENDMICRO-OFFICESCAN-XG-PRE-AUTH-REMOTE-MEMORY-CORRUPTION.txt
- http://packetstormsecurity.com/files/144464/TrendMicro-OfficeScan-11.0-XG-12.0-Memory-Corruption.html
- http://seclists.org/fulldisclosure/2017/Sep/91
- https://www.exploit-db.com/exploits/42920/
#### Github
No PoCs found on GitHub currently.