CVE-2016-7552
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 93%
from disclosure to weapon0 days
Published on NVDApr 12
metasploitApr 10
exploitation probability
93%top 1% of all CVEs
observed exploitation
nono source reports it
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.
Affected products
n/a · n/a