First published: Wed Jan 21 2009(Updated: )
The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Internet Security | =17.0.1224 | |
Trend Micro Internet Security | ||
Trend Micro OfficeScan XG | =8.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3866 is considered a moderate severity vulnerability.
To fix CVE-2008-3866, update to the latest version of Trend Micro OfficeScan or Internet Security that addresses this vulnerability.
CVE-2008-3866 affects Trend Micro OfficeScan 8.0 SP1 and Trend Micro Internet Security 2007 and 2008.
CVE-2008-3866 is a client-side password protection vulnerability in the Trend Micro Personal Firewall service.
CVE-2008-3866 is not typically considered exploitable remotely as it relies on client-side interactions.