← All CVEs

CVE-2007-1070

high · 10

Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.

10
CVSS
73.0%
EPSS (exploit prob.)
99th
EPSS percentile
2007-02-21
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftwindows_2003_serverr2
microsoftwindows_2003_serversp2
microsoftwindows_ntall versions
microsoftwindows_vistaall versions
microsoftwindows_xpall versions
trend_microserverprotect5.58
trend_microserverprotect5.58
trend_microserverprotect5.61
trend_microserverprotect5.62

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-1070