HIGH · 9.3

CVE-2007-0851

Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execut...

Vulnerability Description

Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Trend MicroClient-Server-Messaging Suite Smbgold
Trend MicroClient-Server Suite Smbgold
Trend MicroControl Manager2.5.0
Trend MicroInterscan Emanager3.5
Trend MicroInterscan Messaging Security SuiteAll versions
Trend MicroInterscan Viruswall3.0.1
Trend MicroInterscan Viruswall For Windows Nt3.4
Trend MicroInterscan Viruswall Scan Engine7.510.0-1002
Trend MicroInterscan Web Security SuiteAll versions
Trend MicroInterscan Webmanager1.2
Trend MicroInterscan Webprotectgold
Trend MicroOfficescan3.0
Trend MicroPc-Cillin6.0
Trend MicroPc-Cillin Internet Security14_14.00.1485
Trend MicroPc Cillin - Internet Security 2006All versions
Trend MicroPortalprotect1.0
Trend MicroScanmail1.0.0
Trend MicroScanmail EmanagerAll versions
Trend MicroScanning Engine7.1.0
Trend MicroServerprotect5.3.1

References

FAQ

What is CVE-2007-0851?

CVE-2007-0851 is a vulnerability with a CVSS score of 9.3 (HIGH). Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execut...

How severe is CVE-2007-0851?

CVE-2007-0851 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0851?

Check the references section above for vendor advisories and patch information. Affected products include: Trend Micro Client-Server-Messaging Suite Smb, Trend Micro Client-Server Suite Smb, Trend Micro Control Manager, Trend Micro Interscan Emanager, Trend Micro Interscan Messaging Security Suite.