CVE-2017-14092
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@trendmicro.com — https://success.trendmicro.com/solution/1118486
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| trendmicro | scanmail | 12.0 | |
References
- https://success.trendmicro.com/solution/1118486
- https://www.coresecurity.com/advisories/trend-micro-scanmail-microsoft-exchange-multiple-vulnerabilities
- https://success.trendmicro.com/solution/1118486
- https://www.coresecurity.com/advisories/trend-micro-scanmail-microsoft-exchange-multiple-vulnerabilities
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.