Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96pj-v4p2-qw4v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.

EPSS

Процентиль: 88%
0.03625
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.8
nvd
около 6 лет назад

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.

EPSS

Процентиль: 88%
0.03625
Низкий

Дефекты

CWE-20