7.2

CVE-2007-0856

TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trend Micro ≫ Client-server-messaging Security Version 3.5 Edition smb
Trend Micro ≫ Tmcomm.Sys Version 1.5.1052
Trend Micro ≫ Trend Micro Antispyware Version 3.0_sp2 Edition enterprise
Trend Micro ≫ Trend Micro Antispyware Version 3.2_sp1 Edition smb
Trend Micro ≫ Trend Micro Antispyware Version 3.5 Edition consumer
Trend Micro ≫ Vsapini.Sys Version 3.320.1003
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.95% 0.564
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034432&id=EN-1034432
Patch
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=469
Vendor Advisory
http://osvdb.org/33039
http://secunia.com/advisories/24069
Patch
Vendor Advisory
http://securitytracker.com/id?1017604
http://securitytracker.com/id?1017605
http://securitytracker.com/id?1017606
http://www.kb.cert.org/vuls/id/282240
US Government Resource
http://www.kb.cert.org/vuls/id/666800
US Government Resource
http://www.securityfocus.com/bid/22448
http://www.vupen.com/english/advisories/2007/0521
https://exchange.xforce.ibmcloud.com/vulnerabilities/32353