Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-6222

Severity
7.8HIGH
EPSS
0.4%
top 39.26%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 15
Latest updateMay 13

Description

Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cmrj-247h-f4v8: Arbitrary logs location in Trend Micro Email Encryption Gateway 52022-05-13
CVEList
CVE-2018-6222: Arbitrary logs location in Trend Micro Email Encryption Gateway 52018-03-15

💥Exploits & PoCs

1
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities2018-02-22
CVE-2018-6222 (HIGH CVSS 7.8) | Arbitrary logs location in Trend Mi | cvebase.io