CVE-2017-14089

critical
Published 2017-10-06 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@trendmicro.com — https://success.trendmicro.com/solution/1118372

Application impact

VendorProductVersionsFixed
trendmicroofficescan11.0
trendmicroofficescan12.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.