CVE-2007-4218: Buffer Overflow
Multiple buffer overflows in the ServerProtect service (SpntSvc.exe) in Trend Micro ServerProtect for Windows before 5.58 Security Patch 4 allow remote attackers to execute arbitrary code via certain RPC requests to certain TCP ports that are processed by the (1) RPCFNENGNewManualScan, (2) RPCFNENGTimedNewManualScan, and (3) RPCFNSetComputerName functions in (a) StRpcSrv.dll; the (4) RPCFNCMONSetSvcImpersonateUser and (5) RPCFNOldCMONSetSvcImpersonateUser functions in (b) Stcommon.dll; the (6) RPCFNENGTakeActionOnAFile and (7) RPCFNENGAddTaskExportLogItem functions in (c) Eng50.dll; the (8) NTFSetPagerNotifyConfig function in (d) Notification.dll; or the (9) RPCFNCopyAUSrc function in the (e) ServerProtect Agent service.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4218?
CVE-2007-4218 has a high severity rating due to its ability to allow remote code execution.
How do I fix CVE-2007-4218?
To fix CVE-2007-4218, upgrade Trend Micro ServerProtect for Windows to version 5.58 Security Patch 4 or later.
What vulnerable software is affected by CVE-2007-4218?
CVE-2007-4218 affects Trend Micro ServerProtect for Windows versions prior to 5.58 Security Patch 4.
What types of attacks can be executed through CVE-2007-4218?
CVE-2007-4218 allows remote attackers to execute arbitrary code via specific RPC requests.
Is there a workaround for CVE-2007-4218?
There are no known effective workarounds for CVE-2007-4218; the best mitigation is to apply the security patch.