Vulnerability record · CVE-2018-3604 · published 9 February 2018
CVE-2018-3604: Trend Micro Control Manager GetXXX SQL injection leads to RCE
Trendmicro · Control Manager
Trend Micro Control Manager 6.0 contains SQL injection flaws in multiple GetXXX methods that can be leveraged to execute arbitrary code on vulnerable installations. The vulnerability is remotely reachable over the network with low complexity, though it requires some level of authentication. Because the affected product is a central management console, compromise can expose the managed environment rather than a single endpoint.
Description
GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a central management console with a high EPSS score and a vendor patch available makes this a high-priority fix despite the required low privilege level.
What it is
Trend Micro Control Manager 6.0 contains SQL injection flaws in multiple GetXXX methods that can be leveraged to execute arbitrary code on vulnerable installations. The vulnerability is remotely reachable over the network with low complexity, though it requires some level of authentication. Because the affected product is a central management console, compromise can expose the managed environment rather than a single endpoint.
Impact
An attacker who can reach the affected interface and authenticate at a low-privilege level can execute arbitrary code on the Control Manager server, gaining control of the management host and potentially the systems it administers.
Attack surface
The CVSS vector is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), so the attacker needs some valid access to the product before exploitation. No affected version detail beyond Control Manager 6.0 is provided.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at roughly 0.68 (99th percentile), indicating elevated likelihood of attempted exploitation. Multiple Zero Day Initiative advisories exist, but the record does not state whether public exploit code is available.
What to do
- Apply the vendor patch referenced in the Trend Micro advisory (solution 1119158) as the first action.
- Restrict network access to the Control Manager management interface to trusted administrative networks only.
- Review and reduce accounts with access to Control Manager, removing unnecessary low-privilege users.
- Monitor the vendor advisory for any updated guidance or additional affected builds.
- If patching cannot be done immediately, isolate or tightly firewall the Control Manager server.
Detection
- Inspect web and application logs for SQL metacharacters or injection patterns in requests to Control Manager GetXXX endpoints.
- Alert on unexpected child processes or command execution spawned by the Control Manager service.
- Monitor for anomalous database queries or errors originating from the Control Manager application.
- Track authentication events for low-privilege accounts followed by unusual administrative activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-3604 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-3604), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.