CVE-2007-4218
Multiple buffer overflows in the ServerProtect service (SpntSvc.exe) in Trend Micro ServerProtect for Windows before 5.58 Security Patch 4 allow remote attackers to execute arbitrary code via certain RPC requests to certain TCP ports that are processed by the (1) RPCFN_ENG_NewManualScan, (2) RPCFN_ENG_TimedNewManualScan, and (3) RPCFN_SetComputerName functions in (a) StRpcSrv.dll; the (4) RPCFN_CMON_SetSvcImpersonateUser and (5) RPCFN_OldCMON_SetSvcImpersonateUser functions in (b) Stcommon.dll; the (6) RPCFN_ENG_TakeActionOnAFile and (7) RPCFN_ENG_AddTaskExportLogItem functions in (c) Eng50.dll; the (8) NTF_SetPagerNotifyConfig function in (d) Notification.dll; or the (9) RPCFN_CopyAUSrc function in the (e) ServerProtect Agent service.
EPSS 59.27% · 98.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| trend_micro | serverprotect | 5.58 |
| n/a | n/a | * |
Timeline
- Aug 22, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- VU#109056 third-party-advisory
- 20070821 Trend Micro ServerProtect Multiple Buffer Overflow Vulnerabilities third-party-advisory
- serverprotect-stcommondll-bo(36174) vdb
- 25395 vdb
- serverprotect-notification-bo(36176) vdb
- serverprotect-agent-rpcfncopyausrc-bo(36178) vdb
- 20070907 ZDI-07-050: Trend Micro ServerProtect RPCFN_SetComputerName() Stack Overflow Vulnerability mailing-list
- VU#204448 third-party-advisory
- serverprotect-eng50dll-bo(36175) vdb
- TA07-235A third-party-advisory
- ADV-2007-2934 vdb
- http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch4_readme.txt url
- http://www.zerodayinitiative.com/advisories/ZDI-07-050.html url
- 1018594 vdb
- 3052 third-party-advisory
- serverprotect-strpcsrv-bo(36172) vdb
- 26523 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-4218 advisory