Check Point Reference: | CPAI-2017-0696 |
Date Published: | 17 Aug 2017 |
Severity: | Critical |
Last Updated: | Wednesday 09 November, 2022 |
Source: | Trend Micro |
Industry Reference: | CVE-2017-11394 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Trend Micro OfficeScan prior to 11.0 SP1 CP 6392 r1 Trend Micro OfficeScan XG (12.0) prior to CP 1641 r1 |
Vulnerability Description | A command injection vulnerability exists in Trend Micro's OfficeScan. The vulnerability is due to improper validation of HTTP parameters within the Proxy.php script. A remote, authenticated attacker could exploit the vulnerability by sending a crafted request to the vulnerable system. |
This protection detects attempts to exploit this vulnerability.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Trend Micro ServerProtect Protection Violation.
Attack Information: Trend Micro OfficeScan Proxy.php Command Injection