CVE-2017-9033 describes a Cross-Site Request Forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux versions prior to CP 1531. This flaw allows remote attackers to hijack authenticated user sessions to initiate updates from arbitrary sources due to the absence of anti-CSRF tokens. The vulnerability carries a high CVSS score of 8.8, indicating a critical risk. It can be exploited remotely with low complexity, requiring user interaction, and could lead to high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting low public awareness and limited exploitation interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:trendmicro:serverprotect:3.0:*:*:*:*:linux:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.