CVE-2017-11398
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 8.2%
from disclosure to weapon0 days
Published on NVDJan 19
1st PoCDec 19
exploitation probability
8.2%top 6% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.
Affected products
Trend Micro · Trend Micro Smart Protection Server (Standalone)public PoCs found — 2
exploitdbwww.exploit-db.com/exploits/43388unverifiedcve_referencewww.exploit-db.com/exploits/43388/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.