TippingPoint Zero Day Initiative

Trend Micro Control Manager TMCM_MembershipProvider ValidateUser Password Hash Usage Authentication Bypass Vulnerability

ZDI-18-113: January 10th, 2018


CVSS Score

Affected Vendors

Affected Products

    Control Manager

Vulnerability Details

This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Trend Micro Control Manager. User interaction is not required to exploit this vulnerability.

The specific flaw exists within the handling of challenges for authentication. The implementation of the challenge allows an attacker to authenticate to the system if they have possession of the password hash but not the password for a user. An attacker can leverage this vulnerability in conjunction with other vulnerabilities to bypass authentication.

Vendor Response

Trend Micro has issued an update to correct this vulnerability. More details can be found at:

Disclosure Timeline

    2017-10-17 - Vulnerability reported to vendor
    2018-01-10 - Coordinated public release of advisory


This vulnerability was discovered by:
    Steven Seeley (mr_me) of Offensive Security