Trend Micro Virtual Mobile Infrastructure apns_worker.py Command Injection (CVE-2016-6270)

A remote command execution vulnerability exists in Trend Micro Smart Protection Server. The vulnerability is due to insufficient validation of user-supplied input. A remote, authenticated attacker could exploit this vulnerability by sending a crafted input to the vulnerable system that could lead to arbitrary command execution under the security context of system.

Leave a Reply