ID

VAR-E-201703-0441


CVE

cve_id:CVE-2017-5565

Trust: 0.3

sources: BID: 97031

TITLE

Multiple Trend Micro Products CVE-2017-5565 DLL Loading Local Code Injection Vulnerability

Trust: 0.3

sources: BID: 97031

DESCRIPTION

Multiple Trend Micro products are prone to a local code-injection vulnerability.
A local attacker can exploit this issue to execute arbitrary code in the context of the system running the affected application; this can also result in the attacker gaining complete control of the affected application.
The following products are vulnerable:
Trend Micro Maximum Security 11.0 and prior.
Trend Micro Internet Security 11.0 and prior.
Trend Micro Antivirus+ Security 11.0 and prior.

Trust: 0.3

sources: BID: 97031

AFFECTED PRODUCTS

vendor:trend micromodel:maximum securityscope:eqversion:10.0.1265

Trust: 0.3

vendor:trend micromodel:maximum securityscope:eqversion:8.0.2063

Trust: 0.3

vendor:trend micromodel:maximum securityscope:eqversion:8.0

Trust: 0.3

vendor:trend micromodel:maximum securityscope:eqversion:11.0

Trust: 0.3

vendor:trend micromodel:maximum securityscope:eqversion:10.0.1186

Trust: 0.3

vendor:trend micromodel:maximum securityscope:eqversion:10.0

Trust: 0.3

vendor:trend micromodel:internet securityscope:eqversion:10.0.1265

Trust: 0.3

vendor:trend micromodel:internet securityscope:eqversion:8.0

Trust: 0.3

vendor:trend micromodel:internet securityscope:eqversion:11.0

Trust: 0.3

vendor:trend micromodel:internet securityscope:eqversion:10.0.1186

Trust: 0.3

vendor:trend micromodel:internet securityscope:eqversion:10.0

Trust: 0.3

vendor:trend micromodel:antivirus+ securityscope:eqversion:11.0

Trust: 0.3

sources: BID: 97031

EXPLOIT

The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.

Trust: 0.3

sources: BID: 97031

PRICE

Free

Trust: 0.3

sources: BID: 97031

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 97031

CREDITS

Michael Engstler

Trust: 0.3

sources: BID: 97031

EXTERNAL IDS

db:NVDid:CVE-2017-5565

Trust: 0.3

db:BIDid:97031

Trust: 0.3

sources: BID: 97031

REFERENCES

url:https://cybellum.com/doubleagentzero-day-code-injection-and-persistence-technique/

Trust: 0.3

url:http://www.trend.com

Trust: 0.3

sources: BID: 97031

SOURCES

db:BIDid:97031

LAST UPDATE DATE

2022-07-27T09:56:18.477000+00:00


SOURCES UPDATE DATE

db:BIDid:97031date:2017-03-29T00:01:00

SOURCES RELEASE DATE

db:BIDid:97031date:2017-03-21T00:00:00