Vulnerability Description
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause the server disk space to be consumed with dump files from continuous HTTP requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Officescan | 11.0 |
Related Weaknesses (CWE)
References
- http://hyp3rlinx.altervista.org/advisories/CVE-2017-14086-TRENDMICRO-OFFICESCAN-ExploitThird Party Advisory
- http://packetstormsecurity.com/files/144401/TrendMicro-OfficeScan-11.0-XG-12.0-AThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2017/Sep/88Mailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/541274/100/0/threaded
- http://www.securityfocus.com/bid/101076Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039500Third Party AdvisoryVDB Entry
- https://success.trendmicro.com/solution/1118372PatchVendor Advisory
- https://www.exploit-db.com/exploits/42892/Third Party AdvisoryVDB Entry
- http://hyp3rlinx.altervista.org/advisories/CVE-2017-14086-TRENDMICRO-OFFICESCAN-ExploitThird Party Advisory
- http://packetstormsecurity.com/files/144401/TrendMicro-OfficeScan-11.0-XG-12.0-AThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2017/Sep/88Mailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/541274/100/0/threaded
- http://www.securityfocus.com/bid/101076Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039500Third Party AdvisoryVDB Entry
- https://success.trendmicro.com/solution/1118372PatchVendor Advisory
FAQ
What is CVE-2017-14086?
CVE-2017-14086 is a vulnerability with a CVSS score of 7.5 (HIGH). Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable...
How severe is CVE-2017-14086?
CVE-2017-14086 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14086?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Officescan.