CVE-2018-10357: Trend Micro Endpoint Application Control

High severity, CVSS 8.8. EPSS: 64.7% chance of exploitation in the next 30 days.

A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. Authentication is required to exploit this vulnerability.

Affected products

  • Trend Micro Endpoint Application Control: version 2.0 only

Published 2018-05-23. Last modified 2026-06-17.