ID

VAR-190001-1140


TITLE

Trendmicro IWSS Local Privilege Escalation Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2011-4513 // CNNVD: CNNVD-201110-643

DESCRIPTION

Trendmicro IWSS provides dynamic, integrated security for enterprise networks at the gateway for Web-based attacks. Trendmicro IWSS has a security hole that allows an attacker to gain root access. The program \"patchCmd\" sets the corresponding \"setuid\" and \"setgid\" to allow all users to execute. The code executes setuid(0) before system() to allow ROOT permission to be executed during execution without the user's corresponding permission. According to the input parameter system() of 'patchCmd', two scripts are called: \"./PatchExe.sh\" and \"./RollbackExe.sh\". You can see that the string \"./\" indicates execution in the current directory, and the attacker passes the other PATH creates arbitrary scripts to execute with ROOT privileges. Trendmicro IWSS is prone to a local privilege-escalation vulnerability. Trendmicro IWSS 3.1 is vulnerable; other versions may also be affected

Trust: 0.99

sources: CNVD: CNVD-2011-4513 // BID: 50380 // IVD: 2b4ca414-1f82-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 2b4ca414-1f82-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-4513

AFFECTED PRODUCTS

vendor:trend micromodel:interscan websecuritysuitescope:eqversion:3.1

Trust: 1.1

sources: IVD: 2b4ca414-1f82-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-4513 // BID: 50380

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 2b4ca414-1f82-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

IVD: 2b4ca414-1f82-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 2b4ca414-1f82-11e6-abef-000c29c66e3d

THREAT TYPE

local

Trust: 0.9

sources: BID: 50380 // CNNVD: CNNVD-201110-643

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201110-643

EXTERNAL IDS

db:BIDid:50380

Trust: 1.5

db:CNVDid:CNVD-2011-4513

Trust: 0.8

db:CNNVDid:CNNVD-201110-643

Trust: 0.6

db:IVDid:2B4CA414-1F82-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 2b4ca414-1f82-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-4513 // BID: 50380 // CNNVD: CNNVD-201110-643

REFERENCES

url:http://buguroo.com/adv/bsa-2011-002.txt

Trust: 0.9

url:http://www.securityfocus.com/bid/50380

Trust: 0.6

url:http://us.trendmicro.com/us/products/enterprise/interscan-web-security-suite/

Trust: 0.3

sources: CNVD: CNVD-2011-4513 // BID: 50380 // CNNVD: CNNVD-201110-643

CREDITS

Buguroo Offensive Security

Trust: 0.9

sources: BID: 50380 // CNNVD: CNNVD-201110-643

SOURCES

db:IVDid:2b4ca414-1f82-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-4513
db:BIDid:50380
db:CNNVDid:CNNVD-201110-643

LAST UPDATE DATE

2022-05-17T01:50:41.718000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-4513date:2011-10-27T00:00:00
db:BIDid:50380date:2011-10-26T00:00:00
db:CNNVDid:CNNVD-201110-643date:2011-10-28T00:00:00

SOURCES RELEASE DATE

db:IVDid:2b4ca414-1f82-11e6-abef-000c29c66e3ddate:2011-10-27T00:00:00
db:CNVDid:CNVD-2011-4513date:2011-10-27T00:00:00
db:BIDid:50380date:2011-10-26T00:00:00
db:CNNVDid:CNNVD-201110-643date:1900-01-01T00:00:00