Insufficient verification of data authenticity in ScanMail - CVE-2017-14091
Published: December 16, 2017 / Updated: August 8, 2020
ScanMail
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploited to overwrite sensitive files in the ScanMail for Exchange directory.