Lucene search

K
saintSAINT CorporationSAINT:AE23500C1A77A485F11411651A9AF8F9
HistoryDec 28, 2007 - 12:00 a.m.

Trend Micro ServerProtect RPCFN_CMON_SetSvcImpersonateUser buffer overflow

2007-12-2800:00:00
SAINT Corporation
www.saintcorporation.com
23

EPSS

0.968

Percentile

99.7%

Added: 12/28/2007
CVE: CVE-2007-4218
BID: 25395
OSVDB: 39752

Background

Trend Micro ServerProtect is a virus scanner for servers.

Problem

A buffer overflow in the ServerProtect service allows remote attackers to execute arbitrary commands by sending a specially crafted RPC request which is processed by the **RPCFN_CMON_SetSvcImpersonateUser** function in the **Stcommon.dll** library.

Resolution

Apply ServerProtect 5.58 Security Patch 4 or higher.

References

<http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=587&gt;
<http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch4_readme.txt&gt;

Limitations

Exploit works on Trend Micro ServerProtect 5.58 Security Patch 3.

Platforms

Windows
Windows Server 2003 SP1

EPSS

0.968

Percentile

99.7%