VDB

CVE-2007-0856

CVE-2007-0856 PUBLISHED CVSS 7.199999809265137 HIGH

TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.

EPSS 0.15% · 35.3th percentile

Risk Scores

CVSS 2.0
7.199999809265137
EPSS Score
0.15%
35.3th percentile

Affected Products

VendorProductVersions
trend_microvsapini.sys3.320.1003
n/an/an/a
trend_microtmcomm.sys1.5.1052
trend_microtrend_micro_antivirus2007
trend_microdamage_cleanup_services3.2
trend_microtrend_micro_antispyware3.0_sp2, 3.5, *
trend_microtrend_micro_antirootkit_common_module
trend_microclient-server-messaging_security3.5
trend_micropc-cillin_internet_security2007

Timeline

  • Feb 8, 2007 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›