Software
Command Execution Flaw Patched in Trend Micro Products
Reported by securityweek.com
Trend Micro released patches on Wednesday to address a serious vulnerability affecting several of the company’s products.
Google Project Zero researcher Tavis Ormandy discovered a remote Node.js debugging stub in the default configuration of Trend Micro Antivirus, Maximum Security, Premium Security and Password Manager. The flaw was easy to discover and exploit, Ormandy said.