Vulnerability record · CVE-2017-11391 · published 3 August 2017
CVE-2017-11391: Trend Micro InterScan Messaging Virtual Appliance proxy command injection
Trendmicro · Interscan Messaging Security Virtual Appliance
Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 contain a command injection flaw in the modTMCSS Proxy, reachable by parsing the "t" parameter. An attacker who can reach the proxy can run arbitrary code on the appliance, which sits in the mail path and is therefore a high-value target.
Description
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4744.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in an internet-facing mail security appliance with a very high EPSS score, tempered only by the low-privilege precondition in the CVSS vector.
What it is
Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 contain a command injection flaw in the modTMCSS Proxy, reachable by parsing the "t" parameter. An attacker who can reach the proxy can run arbitrary code on the appliance, which sits in the mail path and is therefore a high-value target.
Impact
Successful exploitation gives the attacker arbitrary code execution on the virtual appliance, with high impact to confidentiality, integrity and availability. From there an attacker could read mail data, alter filtering, or pivot into the internal network.
Attack surface
The flaw is network reachable (AV:N) with low attack complexity and no user interaction, but the CVSS vector requires low privileges (PR:L), so some form of authenticated or otherwise privileged access to the proxy interface is needed. No affected version detail beyond 9.0 and 9.1 is given.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high at roughly 0.62 (99th percentile), indicating elevated likelihood of exploitation activity. Reference tags are advisory-only (ZDI, SecurityFocus, vendor), with no public exploit tag supplied.
What to do
- Apply the vendor fix referenced in Trend Micro solution 1117723; upgrade or patch InterScan Messaging Virtual Appliance 9.0/9.1 as directed.
- Restrict network access to the modTMCSS proxy interface to trusted management hosts only.
- Enforce least privilege and strong authentication for any account able to reach the proxy.
- If the appliance is end-of-life or no fix is available, isolate it on a segmented management VLAN and monitor closely.
- Review appliance configuration for unnecessary exposure of proxy services to untrusted networks.
Detection
- Monitor appliance and host logs for unexpected child processes or shell activity spawned by the proxy service.
- Alert on requests to the modTMCSS proxy carrying unusual or shell-metacharacter content in the "t" parameter.
- Baseline normal proxy traffic and flag anomalous outbound connections from the appliance.
- Watch for file or configuration changes on the appliance outside maintenance windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100075 | Third Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-17-502 | Third Party AdvisoryVDB Entry |
| https://success.trendmicro.com/solution/1117723 | Vendor Advisory |
| http://www.securityfocus.com/bid/100075 | Third Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-17-502 | Third Party AdvisoryVDB Entry |
| https://success.trendmicro.com/solution/1117723 | Vendor Advisory |
Track CVE-2017-11391 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11391), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.