Remote Code Execution Vulnerability in Trend Micro Mobile Security
CVE-2023-32527
8.8HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 26 June 2023
Summary
A vulnerability in Trend Micro Mobile Security (Enterprise) version 9.8 SP5 allows remote attackers to execute arbitrary code through manipulated .php files. To exploit this flaw, attackers must first acquire low-privileged access to the target system. This vulnerability poses significant risks to the security of affected installations, enabling malicious users to potentially lead to further unauthorized actions on the compromised systems. Security teams should ensure prompt mitigation strategies are in place to protect against this threat.
Affected Version(s)
Trend Micro Moibile Security for Enterprise 9.8 SP5 < 9.8.3294
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved