VDB

CVE-2007-1070

CVE-2007-1070 PUBLISHED CVSS 10 CRITICAL

Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.

EPSS 75.11% · 98.9th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
75.11%
98.9th percentile

Affected Products

VendorProductVersions
n/an/an/a
trend_microserverprotect5.58, 5.58, 5.61

Timeline

  • Feb 21, 2007 CVE Published
  • Sep 5, 2007 PoC Published
  • Sep 7, 2007 VulnCheck KEV Exploitation
  • Apr 30, 2010 PoC Published
  • Jun 20, 2017 VulnCheck KEV Exploitation
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›