Vulnerability record · CVE-2017-11394 · published 3 August 2017
CVE-2017-11394: Trend Micro OfficeScan Proxy.php command injection via T parameter
Trendmicro · Officescan
Trend Micro OfficeScan 11 and XG (12) contain a command injection flaw in Proxy.php, where the T parameter is parsed without proper input validation. A remote, unauthenticated attacker can inject commands that execute arbitrary code on the vulnerable installation. The flaw is rated critical (CVSS 9.8) and affects a security product that is itself a high-value target.
Description
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available, and a very high EPSS score make this an urgent patch target.
What it is
Trend Micro OfficeScan 11 and XG (12) contain a command injection flaw in Proxy.php, where the T parameter is parsed without proper input validation. A remote, unauthenticated attacker can inject commands that execute arbitrary code on the vulnerable installation. The flaw is rated critical (CVSS 9.8) and affects a security product that is itself a high-value target.
Impact
Successful exploitation gives the attacker arbitrary code execution on the OfficeScan server, typically with the privileges of the web service. That can lead to full compromise of the endpoint management server and, through it, the managed endpoints.
Attack surface
Reachable over the network through the OfficeScan web interface by sending a crafted request to Proxy.php with a malicious T parameter. The CVSS vector shows no privileges required and no user interaction, so it is remotely exploitable without authentication.
Exploitation
Not listed in CISA KEV, but EPSS is 0.66774 (99.255th percentile) and a public Exploit-DB entry (42971) exists, indicating exploit code is available and exploitation is likely.
What to do
- Apply the vendor patch from Trend Micro solution 1117769 immediately on OfficeScan 11 and XG (12) servers.
- If patching cannot be done at once, restrict network access to the OfficeScan web interface to trusted management networks only.
- Review and harden the web service account so it runs with the least privileges needed.
- Monitor the vendor advisory for any additional interim mitigation guidance.
Detection
- Inspect web server and OfficeScan logs for requests to Proxy.php containing suspicious or shell metacharacters in the T parameter.
- Alert on unexpected child processes spawned by the OfficeScan web service (for example cmd.exe, /bin/sh, or scripting interpreters).
- Monitor for outbound connections from the OfficeScan server to unknown hosts that could indicate command-and-control or payload retrieval.
- Audit file system and configuration changes on the OfficeScan server for signs of post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100130 | Third Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-17-521 | Third Party AdvisoryVDB Entry |
| https://success.trendmicro.com/solution/1117769 | MitigationPatchVendor Advisory |
| https://www.exploit-db.com/exploits/42971/ | |
| http://www.securityfocus.com/bid/100130 | Third Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-17-521 | Third Party AdvisoryVDB Entry |
| https://success.trendmicro.com/solution/1117769 | MitigationPatchVendor Advisory |
| https://www.exploit-db.com/exploits/42971/ |
Track CVE-2017-11394 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11394), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.