High severity7.5NVD Advisory· Published Oct 6, 2017· Updated May 13, 2026
CVE-2017-14087
CVE-2017-14087
Description
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
Affected products
3cpe:2.3:a:trendmicro:officescan:11.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:trendmicro:officescan:11.0:*:*:*:*:*:*:*
- cpe:2.3:a:trendmicro:officescan:12.0:*:*:*:*:*:*:*
- Trend Micro/Trend Micro OfficeScanv5Range: XG (12.0)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- hyp3rlinx.altervista.org/advisories/CVE-2017-14087-TRENDMICRO-OFFICESCAN-XG-HOST-HEADER-INJECTION.txtnvdExploitThird Party Advisory
- packetstormsecurity.com/files/144404/TrendMicro-OfficeScan-11.0-XG-12.0-Host-Header-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2017/Sep/86nvdExploitMailing ListThird Party Advisory
- www.exploit-db.com/exploits/42895/nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/101074nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039500nvdThird Party AdvisoryVDB Entry
- success.trendmicro.com/solution/1118372nvdMitigationVendor Advisory
- www.securityfocus.com/archive/1/541267/100/0/threadednvd
News mentions
0No linked articles in our index yet.