Lucene search

K
saintSAINT CorporationSAINT:43E3B9A4B59C08152CD331DFA63F5434
HistoryAug 23, 2007 - 12:00 a.m.

Trend Micro ServerProtect RPC NTF_SetPagerNotifyConfig buffer overflow

2007-08-2300:00:00
SAINT Corporation
download.saintcorporation.com
21

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.968

Percentile

99.7%

Added: 08/23/2007
CVE: CVE-2007-4218
BID: 25395
OSVDB: 39754

Background

ServerProtect is a virus scanner for servers.

Problem

A buffer overflow in the NTF_SetPagerNotifyConfig function within the **Notification.dll** library allows remote attackers to execute arbitrary commands by sending a specially crafted RPC request to port 5168/TCP.

Resolution

Apply ServerProtect 5.58 Security Patch 4.

References

<http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=587&gt;

Limitations

Exploit works on Trend Micro ServerProtect 5.58 with Patch 3.

Platforms

Windows

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.968

Percentile

99.7%