Vulnerability record · CVE-2018-3606 · published 9 February 2018
CVE-2018-3606: Trend Micro Control Manager SQL injection leads to remote code execution
Trendmicro · Control Manager
Trend Micro Control Manager 6.0 contains SQL injection flaws in the XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance methods that can be chained into remote code execution. Because the vulnerable component is a management server, successful exploitation gives an attacker code execution on a central console rather than a low-value endpoint.
Description
XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable SQL injection that leads to code execution on a central management server, with high EPSS despite no KEV listing.
What it is
Trend Micro Control Manager 6.0 contains SQL injection flaws in the XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance methods that can be chained into remote code execution. Because the vulnerable component is a management server, successful exploitation gives an attacker code execution on a central console rather than a low-value endpoint.
Impact
An attacker who can reach the affected methods can execute arbitrary code on the Control Manager installation, gaining the privileges of that service and potentially control over managed endpoints and data.
Attack surface
The CVSS vector is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), so the attacker needs some authenticated access to the product before exploiting the injection. No affected version detail beyond Control Manager 6.0 is given in the record.
Exploitation
The record shows no CISA KEV listing and no ransomware association, but EPSS is high at roughly 0.49 (98.8th percentile), indicating meaningful predicted exploitation activity; references are vendor patch and Zero Day Initiative advisories only, with no public exploit tag.
What to do
- Apply the Trend Micro patch referenced in solution 1119158 as the first action.
- Restrict network access to the Control Manager management interface to trusted administrative networks.
- Enforce least privilege and review which accounts can reach the affected methods.
- Monitor and alert on unexpected outbound or process activity from the Control Manager host.
- If patching cannot be done immediately, isolate the server and limit authenticated access.
Detection
- Review Control Manager and database logs for SQL syntax errors or anomalous queries tied to the XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance methods.
- Hunt for unusual child processes or command execution spawned by the Control Manager service.
- Alert on authentication and request patterns to those methods from unexpected source addresses or accounts.
- Correlate web/server logs with database error bursts that may indicate injection attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-3606 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-3606), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.