Check Point Reference: | CPAI-2007-097 |
Date Published: | 21 Aug 2007 |
Severity: | High |
Last Updated: | Monday 01 January, 2007 |
Source: | Secunia Advisory: SA25186 |
Industry Reference: | CVE-2007-2508 |
Protection Provided by: | |
Who is Vulnerable? | Trend Micro ServerProtect 5.58 |
Vulnerability Description | A buffer overflow vulnerability has been reported in Trend Micro ServerProtect. Trend Micro ServerProtect is a centrally managed virus protection console for enterprise-class servers. A remote attacker may exploit this issue to execute arbitrary code on a vulnerable system via a specially crafted RPC request. |
Update/Patch Avaliable | Apply patches: Trendmicro2 Trendmicro3 |
Vulnerability Details | The vulnerability is due to a boundary error in the EarthAgent (EarthAgent.exe) daemon, the vulnerable component of Trend Micro ServerProtect, that fails to properly handle malformed RPC requests. A remote attacker could specially craft a malicious RPC request that will cause the system to execute arbitrary commands. |