CVE-2000-0204: Medium severity Trend Micro OfficeScan vulnerability
The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utilization to 100%.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the OfficeScan client component that listens on TCP port 12345 or reconfigure it so it does not accept external connections on that port.
Trend Micro OfficeScan client listening on TCP port 12345 = disabled - Compensating control
Block or restrict network access to TCP port 12345 at perimeter and host-based firewalls. Allow connections to that port only from trusted management IPs or internal administration networks.
- Operational
Detect and alert on multiple simultaneous connections to port 12345 (5 or more). Throttle or terminate offending connections and investigate hosts generating the connections to prevent CPU exhaustion.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0204?
CVE-2000-0204 is classified as a denial of service vulnerability due to its impact on system availability.
How do I fix CVE-2000-0204?
To fix CVE-2000-0204, ensure that your Trend Micro OfficeScan client is updated to the latest version that addresses this vulnerability.
What is the affected software for CVE-2000-0204?
The affected software for CVE-2000-0204 is Trend Micro OfficeScan version 3.5.
What does CVE-2000-0204 do?
CVE-2000-0204 allows remote attackers to raise the CPU utilization of the Trend Micro OfficeScan client to 100% by making multiple connections.
Can CVE-2000-0204 be exploited remotely?
Yes, CVE-2000-0204 can be exploited remotely by attackers targeting the OfficeScan client.