A service DLL preloading vulnerability in Trend Micro Encryption for Email versions 5.6 and below could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable system.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://success.trendmicro.com/solution/1118796 | patch vendor advisory |
https://fortiguard.com/zeroday/FG-VD-17-079 | third party advisory |