CVE-2018-6237: Trend Micro Smart Protection Server

High severity, CVSS 7.5. EPSS: 6.3% chance of exploitation in the next 30 days.

A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial of service (DoS) situation.

Affected products

  • Trend Micro Smart Protection Server: version 3.0 only; version 3.1 only; version 3.2 only; version 3.3 only

Published 2018-05-25. Last modified 2026-06-17.