HIGH · 7.2

CVE-2007-0856

TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-...

Vulnerability Description

TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Trend MicroClient-Server-Messaging Security3.5
Trend MicroDamage Cleanup Services3.2
Trend MicroPc-Cillin Internet Security2007
Trend MicroTmcomm.Sys1.5.1052
Trend MicroTrend Micro Antirootkit Common ModuleAll versions
Trend MicroTrend Micro Antispyware3.0_sp2
Trend MicroTrend Micro Antivirus2007
Trend MicroVsapini.Sys3.320.1003

References

FAQ

What is CVE-2007-0856?

CVE-2007-0856 is a vulnerability with a CVSS score of 7.2 (HIGH). TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-...

How severe is CVE-2007-0856?

CVE-2007-0856 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0856?

Check the references section above for vendor advisories and patch information. Affected products include: Trend Micro Client-Server-Messaging Security, Trend Micro Damage Cleanup Services, Trend Micro Pc-Cillin Internet Security, Trend Micro Tmcomm.Sys, Trend Micro Trend Micro Antirootkit Common Module.