PT-2007-2498 · Network Appliance+2 · Network Appliance Filer+3
Pedram Amini
·
Published
2007-02-21
·
Updated
2018-10-16
·
CVE-2007-1070
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Trend Micro ServerProtect for Windows versions 5.58
EMC versions 5.58
Network Appliance Filer versions 5.61 through 5.62
Description:
The issue allows remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll, triggering overflows when calling specific functions. The affected functions include (1) CMON NetTestConnection, (2) CMON ActiveUpdate, and (3) CMON ActiveRollback in StCommon.dll, as well as (4) ENG SetRealTimeScanConfigInfo and (5) ENG SendEMail in eng50.dll.
Recommendations:
For Trend Micro ServerProtect for Windows version 5.58, consider disabling the CMON NetTestConnection, CMON ActiveUpdate, and CMON ActiveRollback functions in StCommon.dll, and the ENG SetRealTimeScanConfigInfo and ENG SendEMail functions in eng50.dll until a patch is available.
For EMC version 5.58, consider disabling the CMON NetTestConnection, CMON ActiveUpdate, and CMON ActiveRollback functions in StCommon.dll, and the ENG SetRealTimeScanConfigInfo and ENG SendEMail functions in eng50.dll until a patch is available.
For Network Appliance Filer versions 5.61 through 5.62, consider disabling the CMON NetTestConnection, CMON ActiveUpdate, and CMON ActiveRollback functions in StCommon.dll, and the ENG SetRealTimeScanConfigInfo and ENG SendEMail functions in eng50.dll until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emc
Network Appliance Filer
Trend Micro Serverprotect For Windows
Trend Micro Serverprotect