VDB
CVE-2007-1070
CVE-2007-1070
PUBLISHED
CVSS 10 CRITICAL
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.
EPSS 75.11% · 98.9th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
75.11%
98.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| trend_micro | serverprotect | 5.58, 5.58, 5.61 |
Timeline
- Feb 21, 2007 CVE Published
- Sep 5, 2007 PoC Published
- Sep 7, 2007 VulnCheck KEV Exploitation
- Apr 30, 2010 PoC Published
- Jun 20, 2017 VulnCheck KEV Exploitation
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
References
- http://www.tippingpoint.com/security/advisories/TSRT-07-01.html url
- VU#466609 third-party-advisory
- http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch1_readme.txt url
- 24243 third-party-advisory
- 33042 vdb
- VU#630025 third-party-advisory
- 20070220 TSRT-07-02: Trend Micro ServerProtect eng50.dll Stack Overflow Vulnerabilities mailing-list
- 20070220 TSRT-07-01: Trend Micro ServerProtect StCommon.dll Stack Overflow Vulnerabilities mailing-list
- VU#730433 third-party-advisory
- serverprotect-eng50-bo(32594) vdb
- http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290 url
- 22639 vdb
- ADV-2007-0670 vdb
- http://www.tippingpoint.com/security/advisories/TSRT-07-02.html url
- VU#349393 third-party-advisory
- serverprotect-stcommon-bo(32601) vdb
- 1017676 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-1070 advisory