Vulnerability Description
The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trend Micro | Internet Security 2007 | All versions |
| Trend Micro | Internet Security 2008 | 17.0.1224 |
| Trend Micro | Officescan | 8.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/31160PatchVendor Advisory
- http://secunia.com/advisories/33609PatchVendor Advisory
- http://secunia.com/secunia_research/2008-43/Vendor Advisory
- http://www.securityfocus.com/bid/33358Patch
- http://www.securitytracker.com/id?1021616
- http://www.securitytracker.com/id?1021617
- http://www.trendmicro.com/ftp/documentation/readme/OSCE8.0_SP1_Patch1_CriticalPaVendor Advisory
- http://www.vupen.com/english/advisories/2009/0191
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48108
- http://secunia.com/advisories/31160PatchVendor Advisory
- http://secunia.com/advisories/33609PatchVendor Advisory
- http://secunia.com/secunia_research/2008-43/Vendor Advisory
- http://www.securityfocus.com/bid/33358Patch
- http://www.securitytracker.com/id?1021616
- http://www.securitytracker.com/id?1021617
FAQ
What is CVE-2008-3866?
CVE-2008-3866 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008...
How severe is CVE-2008-3866?
CVE-2008-3866 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3866?
Check the references section above for vendor advisories and patch information. Affected products include: Trend Micro Internet Security 2007, Trend Micro Internet Security 2008, Trend Micro Officescan.