Vulnerability Description
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Officescan | 11.0 |
Related Weaknesses (CWE)
References
- http://hyp3rlinx.altervista.org/advisories/CVE-2017-14085-TRENDMICRO-OFFICESCAN-ExploitThird Party Advisory
- http://packetstormsecurity.com/files/144402/TrendMicro-OfficeScan-11.0-XG-12.0-IExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2017/Sep/85Mailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/541281/100/0/threaded
- http://www.securityfocus.com/bid/101076Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039500Third Party AdvisoryVDB Entry
- https://success.trendmicro.com/solution/1118372PatchVendor Advisory
- https://www.exploit-db.com/exploits/42893/ExploitThird Party AdvisoryVDB Entry
- http://hyp3rlinx.altervista.org/advisories/CVE-2017-14085-TRENDMICRO-OFFICESCAN-ExploitThird Party Advisory
- http://packetstormsecurity.com/files/144402/TrendMicro-OfficeScan-11.0-XG-12.0-IExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2017/Sep/85Mailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/541281/100/0/threaded
- http://www.securityfocus.com/bid/101076Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039500Third Party AdvisoryVDB Entry
- https://success.trendmicro.com/solution/1118372PatchVendor Advisory
FAQ
What is CVE-2017-14085?
CVE-2017-14085 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version an...
How severe is CVE-2017-14085?
CVE-2017-14085 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14085?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Officescan.