<> Trend Micro Incorporated February 12, 2018 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Trend Micro(TM) Smart Protection Server 3.0 Critical Patch - Build 1355 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Contents =================================================================== 1. Overview of This Critical Patch Release 1.1 Resolved Issues 1.2 Files Included in This Release 2. Documentation Set 3. System Requirements 4. Installation 4.1 Installing 4.2 Uninstalling 5. Post-installation Configuration 6. Known Issues 7. Release History 8. Contact Information 9. About Trend Micro 10. License Agreement =================================================================== 1. Overview of this Critical Patch Release ======================================================================= Install this critical patch to upgrade system resource packages to remove a critical vulnerability Smart Protection Server 3.0. 1.1 Resolved Issues ==================================================================== This critical patch resolves the following issues: Issue: Smart Protection Server 3.0 has an authentication bypass vulnerability that allows command injection with invalid user access information to gain full access. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: This critical patch resolves the vulnerability with enhanced authentication. 1.2 Files Included in this Release ==================================================================== A. Files for Current Issues -------------------------------------------------------------------- Filename Build No. -------------------------------------------------------------------- tmsss-service-patch-3.0-1012.x86_64.tgz 3.0.1355 B. Files for Previous Issues -------------------------------------------------------------------- Not applicable. 2. Documentation Set ======================================================================= To download or view electronic versions of the documentation set for this product, go to http://docs.trendmicro.com 3. System Requirements ======================================================================= You must install Smart Protection Server 3.0 Patch 2 before installing this critical patch. 4. Installation ======================================================================= This section explains key steps for installing the critical patch. 4.1 Installing ==================================================================== To install: 1. Extract the files from the critical patch package to a temporary folder. 2. Log on to the Smart Protection Server web console using an account with administrator privileges. 3. Click "Updates > Program" on the main menu. 4. In the "Upload Component" section, browse to the correct folder, select the "tmsss-service-patch-3.0-1012.x86_64.tgz" critical patch file, and click "Upload". After the server loads the package, information on the available program files appear. This is needed to restart the server. 5. Click the "Update Now" button if you have no concerns. After the update process is completed, the current version of Smart Protection Server becomes 1012. 4.2 Uninstallation ==================================================================== No special uninstallation instructions are provided. 5. Post-installation Configuration ======================================================================= No post-installation steps are required. 6. Known Issues ======================================================================= There are no known issues for this critical patch release. 7. Release History ======================================================================= For more information about updates to this product, go to: http://www.trendmicro.com/download 8. Contact Information ======================================================================= A license to Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, you must renew Maintenance on an annual basis at Trend Micro's then-current Maintenance fees. Contact Trend Micro via fax, phone, and email, or visit our website to download evaluation copies of Trend Micro products. http://www.trendmicro.com/us/about-us/contact/index.html NOTE: This information is subject to change without notice. 9. About Trend Micro ======================================================================= Smart, simple, security that fits As a global leader in IT security, Trend Micro develops innovative security solutions that make the world safe for businesses and consumers to exchange digital information. Copyright 2018, Trend Micro Incorporated. All rights reserved. Trend Micro and the t-ball logo are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other marks are the trademarks or registered trademarks of their respective companies. 10. License Agreement ======================================================================= View information about your license agreement with Trend Micro at: http://www.trendmicro.com/us/about-us/legal-policies/ license-agreements Third-party licensing agreements can be viewed: - By selecting the "About" option in the application user interface - By referring to the "Legal" page of the Administrator's Guide