RULE(RULE ID:712813)

Rule General Information
Release Date: 2019-04-26
Rule Name: Trend Micro Control Manager cmdHandlerTVCSCommander SQL Injection Vulnerability (CVE-2017-11383)
Severity:
CVE ID:
Rule Protection Details
Description: SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:100078
SecurityTrackerID:1039049
ZeroDayInitiative:ZDI-17-493
https://success.trendmicro.com/solution/1117722
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://success.trendmicro.com/solution/1117722