← Vulnerability feed

Vulnerability record · CVE-2018-3606 · published 9 February 2018

CVE-2018-3606: Trend Micro Control Manager SQL injection leads to remote code execution

Trendmicro · Control Manager

Trend Micro Control Manager 6.0 contains SQL injection flaws in the XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance methods that can be chained into remote code execution. Because the vulnerable component is a management server, successful exploitation gives an attacker code execution on a central console rather than a low-value endpoint.

8.8 CVSS 3.0 High EPSS 49% · top 1.2% CWE-89 · SQL injection
8.8CVSS 3.0 base score, v2 6.5
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References
17 Jun 2026Last modified by NVD

Description

XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityNetwork-reachable SQL injection that leads to code execution on a central management server, with high EPSS despite no KEV listing.

What it is

Trend Micro Control Manager 6.0 contains SQL injection flaws in the XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance methods that can be chained into remote code execution. Because the vulnerable component is a management server, successful exploitation gives an attacker code execution on a central console rather than a low-value endpoint.

Impact

An attacker who can reach the affected methods can execute arbitrary code on the Control Manager installation, gaining the privileges of that service and potentially control over managed endpoints and data.

Attack surface

The CVSS vector is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), so the attacker needs some authenticated access to the product before exploiting the injection. No affected version detail beyond Control Manager 6.0 is given in the record.

Exploitation

The record shows no CISA KEV listing and no ransomware association, but EPSS is high at roughly 0.49 (98.8th percentile), indicating meaningful predicted exploitation activity; references are vendor patch and Zero Day Initiative advisories only, with no public exploit tag.

What to do

  • Apply the Trend Micro patch referenced in solution 1119158 as the first action.
  • Restrict network access to the Control Manager management interface to trusted administrative networks.
  • Enforce least privilege and review which accounts can reach the affected methods.
  • Monitor and alert on unexpected outbound or process activity from the Control Manager host.
  • If patching cannot be done immediately, isolate the server and limit authenticated access.

Detection

  • Review Control Manager and database logs for SQL syntax errors or anomalous queries tied to the XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance methods.
  • Hunt for unusual child processes or command execution spawned by the Control Manager service.
  • Alert on authentication and request patterns to those methods from unexpected source addresses or accounts.
  • Correlate web/server logs with database error bursts that may indicate injection attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://success.trendmicro.com/solution/1119158 PatchVendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-18-083/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-085/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-086/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-089/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-091/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-092/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-093/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-099/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-100/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-101/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-103/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-104/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-105/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-106/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-107/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-108/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-110/ Third Party AdvisoryVDB Entry
https://success.trendmicro.com/solution/1119158 PatchVendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-18-083/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-085/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-086/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-089/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-091/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-092/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-093/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-099/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-100/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-101/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-103/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-104/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-105/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-106/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-107/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-108/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-18-110/ Third Party AdvisoryVDB Entry

Track CVE-2018-3606 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-10511Trendmicro control manager server-side request forgery (ssrf) vulnerabilityA vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack …EPSS 2.7%9.8CVE-2018-10510Trendmicro control manager path traversal vulnerabilityA Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute ar…EPSS 6.5%9.8CVE-2018-3601Trendmicro control manager improper authentication vulnerabilityA password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication o…EPSS 4.2%9.8CVE-2017-11383Trendmicro control manager sql injection vulnerabilitySQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validatio…EPSS 38%9.8CVE-2017-11384Trendmicro control manager sql injection vulnerabilitySQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validatio…EPSS 38%9.8CVE-2017-11385Trendmicro control manager sql injection vulnerabilitySQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validatio…EPSS 38%9.8CVE-2017-11386Trendmicro control manager sql injection vulnerabilitySQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validatio…EPSS 24%9.8CVE-2017-11389Trendmicro control manager path traversal vulnerabilityDirectory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2018-3606), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.