The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.
| Software | From | Fixed in |
|---|---|---|
| trend_micro / officescan | 3.11 | 3.11.x |
| trend_micro / officescan | 3.5 | 3.5.x |
| trend_micro / officescan | 3.0 | 3.0.x |
| trend_micro / virus_buster | 3.52 | 3.52.x |
| trend_micro / virus_buster | 3.53 | 3.53.x |
| trend_micro / officescan | 3.1.1 | 3.1.1.x |
| trend_micro / officescan | 3.13 | 3.13.x |
| trend_micro / officescan | 3.54 | 3.54.x |
| trend_micro / virus_buster | 3.54 | 3.54.x |