Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038548 | third party advisory vdb entry |
https://success.trendmicro.com/solution/1117411 | patch vendor advisory |
https://www.coresecurity.com/advisories/trend-micro-serverprotect-multiple-vulnerabilities | third party advisory exploit technical description |
http://seclists.org/fulldisclosure/2017/May/91 | mailing list third party advisory exploit |
http://packetstormsecurity.com/files/142645/Trend-Micro-ServerProtect-Disclosure-CSRF-XSS.html | third party advisory vdb entry exploit |