CVE-2007-3455: Critical severity Trend Micro OfficeScan vulnerability
cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3455?
CVE-2007-3455 is considered a high severity vulnerability due to the potential for unauthorized access to the Management Console.
How do I fix CVE-2007-3455?
To fix CVE-2007-3455, upgrade to a version of Trend Micro OfficeScan that is 8.0.0.142 or later.
What types of systems are affected by CVE-2007-3455?
CVE-2007-3455 affects Trend Micro OfficeScan Corporate Edition version 8.0.
Can CVE-2007-3455 allow remote access?
Yes, CVE-2007-3455 enables remote attackers to bypass the password requirement and access the Management Console.
What is the impact of exploiting CVE-2007-3455?
Exploiting CVE-2007-3455 can lead to unauthorized control over the security management functions of the affected software.