In association with heise online

8 May 2007, 12:37

Trend Micro's ServerProtect executes injected code

Trend Micro's ServerProtect anti-virus solution contains vulnerabilities which can be exploited by attackers to execute their own code on affected systems. The Zero Day Initiative has reported bugs in two components of the software which listen for incoming connections and are therefore remotely exploitable.

The current version of ServerProtect, version 5.58, is affected. Trend Micro has made updates available to fix the security vulnerabilities. Administrators of ServerProtect installations should install these as soon as possible.

Non-authenticated attackers can provoke a buffer overflow in the EarthAgent.exe component, which listens on port 3628 using Remote Procedure Call (RPC). A comparable bug is present in the SpntSvc.exe service, which is by default accessible from the outside world via port 5168.

See also:

(mba)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit







The H open source

The H Security

The H Internet Toolkit