← Vulnerability feed

Vulnerability record · CVE-2018-3604 · published 9 February 2018

CVE-2018-3604: Trend Micro Control Manager GetXXX SQL injection leads to RCE

Trendmicro · Control Manager

Trend Micro Control Manager 6.0 contains SQL injection flaws in multiple GetXXX methods that can be leveraged to execute arbitrary code on vulnerable installations. The vulnerability is remotely reachable over the network with low complexity, though it requires some level of authentication. Because the affected product is a central management console, compromise can expose the managed environment rather than a single endpoint.

8.8 CVSS 3.0 High EPSS 68% · top 0.7% CWE-89 · SQL injection
8.8CVSS 3.0 base score, v2 6.5
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution in a central management console with a high EPSS score and a vendor patch available makes this a high-priority fix despite the required low privilege level.

What it is

Trend Micro Control Manager 6.0 contains SQL injection flaws in multiple GetXXX methods that can be leveraged to execute arbitrary code on vulnerable installations. The vulnerability is remotely reachable over the network with low complexity, though it requires some level of authentication. Because the affected product is a central management console, compromise can expose the managed environment rather than a single endpoint.

Impact

An attacker who can reach the affected interface and authenticate at a low-privilege level can execute arbitrary code on the Control Manager server, gaining control of the management host and potentially the systems it administers.

Attack surface

The CVSS vector is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), so the attacker needs some valid access to the product before exploitation. No affected version detail beyond Control Manager 6.0 is provided.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at roughly 0.68 (99th percentile), indicating elevated likelihood of attempted exploitation. Multiple Zero Day Initiative advisories exist, but the record does not state whether public exploit code is available.

What to do

  • Apply the vendor patch referenced in the Trend Micro advisory (solution 1119158) as the first action.
  • Restrict network access to the Control Manager management interface to trusted administrative networks only.
  • Review and reduce accounts with access to Control Manager, removing unnecessary low-privilege users.
  • Monitor the vendor advisory for any updated guidance or additional affected builds.
  • If patching cannot be done immediately, isolate or tightly firewall the Control Manager server.

Detection

  • Inspect web and application logs for SQL metacharacters or injection patterns in requests to Control Manager GetXXX endpoints.
  • Alert on unexpected child processes or command execution spawned by the Control Manager service.
  • Monitor for anomalous database queries or errors originating from the Control Manager application.
  • Track authentication events for low-privilege accounts followed by unusual administrative activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-3604 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-10511Trendmicro control manager server-side request forgery (ssrf) vulnerabilityA vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack …EPSS 2.7%9.8CVE-2018-10510Trendmicro control manager path traversal vulnerabilityA Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute ar…EPSS 6.5%9.8CVE-2018-3601Trendmicro control manager improper authentication vulnerabilityA password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication o…EPSS 4.2%9.8CVE-2017-11383Trendmicro control manager sql injection vulnerabilitySQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validatio…EPSS 38%9.8CVE-2017-11384Trendmicro control manager sql injection vulnerabilitySQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validatio…EPSS 38%9.8CVE-2017-11385Trendmicro control manager sql injection vulnerabilitySQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validatio…EPSS 38%9.8CVE-2017-11386Trendmicro control manager sql injection vulnerabilitySQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validatio…EPSS 24%9.8CVE-2017-11389Trendmicro control manager path traversal vulnerabilityDirectory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2018-3604), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.