Vulnerability record · CVE-2017-14078 · published 22 September 2017
CVE-2017-14078: Trend Micro Mobile Security SQL injection allows remote code execution
Trendmicro · Mobile Security
Trend Micro Mobile Security (Enterprise) before 9.7 Patch 3 contains SQL injection vulnerabilities that let remote attackers execute arbitrary code on vulnerable installations. The flaw is network-reachable with no authentication or user interaction required, and the vendor's own advisory set (ZDI-17-739 through ZDI-17-763) indicates multiple injection points rather than a single one.
Description
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.0 base score of 9.8 with network-only, unauthenticated, no-interaction access and code execution impact, plus a high EPSS percentile, makes this an urgent patch target despite no KEV listing.
What it is
Trend Micro Mobile Security (Enterprise) before 9.7 Patch 3 contains SQL injection vulnerabilities that let remote attackers execute arbitrary code on vulnerable installations. The flaw is network-reachable with no authentication or user interaction required, and the vendor's own advisory set (ZDI-17-739 through ZDI-17-763) indicates multiple injection points rather than a single one.
Impact
An unauthenticated remote attacker can inject SQL and, per the description, achieve arbitrary code execution on the affected installation, giving full control of the server-side component. That means data disclosure, data modification and service takeover in one step.
Attack surface
Reached over the network (AV:N) with low complexity, no privileges and no user interaction (PR:N/UI:N), so any exposed Mobile Security (Enterprise) instance is directly attackable. The record does not specify which endpoints or parameters are vulnerable; the ZDI advisories would carry that detail.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.50166 (98.85th percentile), indicating a high modeled likelihood of exploitation activity. All references are third-party advisory or VDB entries, so no public exploit code is confirmed by this record.
What to do
- Upgrade Trend Micro Mobile Security (Enterprise) to 9.7 Patch 3 or later; this is the only fix identified in the record.
- If immediate patching is not possible, restrict network access to the Mobile Security management/server interfaces to trusted administrative networks only.
- Place the product behind a reverse proxy or WAF with SQL injection rules as a temporary compensating control, and monitor for bypasses.
- Audit database accounts used by the product for least privilege so a successful injection cannot escalate to code execution or broad data access.
- Verify no unauthorized changes to the underlying database and application files after any suspected exposure.
Detection
- Review web and application logs for SQL metacharacters (quotes, UNION, stacked queries, comment sequences) in requests to Mobile Security endpoints.
- Alert on unexpected database errors or verbose SQL error responses returned by the product.
- Monitor for anomalous child processes or command execution spawned by the Mobile Security service or its database user.
- Baseline and alert on unusual outbound connections or file writes from the Mobile Security server host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-14078 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-14078), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.