CVE-2017-11389: Trend Micro Control Manager

Critical severity, CVSS 9.8. EPSS: 27.2% chance of exploitation in the next 30 days.

Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.

Affected products

Published 2017-08-02. Last modified 2026-06-17.