Risk: Medium
Secunia Research has discovered a vulnerability in Trend Micro OfficeScan, which may be exploited by malicious people to bypass authentication.
The vulnerability is caused due to insufficient entropy in a random session token used to identify an authenticated manager using the web console. An attacker can impersonate a currently logged on manager by predicting the authentication token.
The vulnerability can be further exploited to execute arbitrary code.