Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2018-6222

Description

Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.

POC

Reference

- https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities

- https://www.exploit-db.com/exploits/44166/

Github

- https://github.com/lean0x2F/lean0x2f.github.io