CVE-2017-11392
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 34%
from disclosure to weapon65 days
Published on NVDAug 3
metasploit+65d
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.