Vulnerability Description
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trend Micro | Control Manager | <= 5.5 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/47114Vendor Advisory
- http://www.securityfocus.com/archive/1/520780/100/0/threaded
- http://www.securitytracker.com/id?1026390
- http://www.trendmicro.com/ftp/documentation/readme/readme_critical_patch_TMCM55_Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-11-345/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71681
- http://secunia.com/advisories/47114Vendor Advisory
- http://www.securityfocus.com/archive/1/520780/100/0/threaded
- http://www.securitytracker.com/id?1026390
- http://www.trendmicro.com/ftp/documentation/readme/readme_critical_patch_TMCM55_Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-11-345/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71681
FAQ
What is CVE-2011-5001?
CVE-2011-5001 is a vulnerability with a CVSS score of 10.0 (HIGH). Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attack...
How severe is CVE-2011-5001?
CVE-2011-5001 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-5001?
Check the references section above for vendor advisories and patch information. Affected products include: Trend Micro Control Manager.