CVE-2017-14092: Trend Micro Scanmail
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
Affected products
- Trend Micro Scanmail: version 12.0 only
Published 2017-12-16. Last modified 2026-06-17.