Files
CVEs-PoC/2017/CVE-2017-14089.md
T
2025-09-29 21:09:30 +02:00

21 lines
1.0 KiB
Markdown

### [CVE-2017-14089](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14089)
![](https://img.shields.io/static/v1?label=Product&message=Trend%20Micro%20OfficeScan&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=11.0%2C%20XG%20(12.0)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Unauthorized%20Memory%20Corruption&color=brightgreen)
### Description
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.
### POC
#### Reference
- http://hyp3rlinx.altervista.org/advisories/CVE-2017-14089-TRENDMICRO-OFFICESCAN-XG-PRE-AUTH-REMOTE-MEMORY-CORRUPTION.txt
- http://packetstormsecurity.com/files/144464/TrendMicro-OfficeScan-11.0-XG-12.0-Memory-Corruption.html
- http://seclists.org/fulldisclosure/2017/Sep/91
- https://www.exploit-db.com/exploits/42920/
#### Github
No PoCs found on GitHub currently.