Integer Overflow Vulnerability in Trend Micro ServerProtect for Windows
CVE-2007-4219

Currently unrated

Key Information:

Vendor
CVE Published:
22 August 2007

Summary

An integer overflow vulnerability exists within the RPCFN_SYNC_TASK function in StRpcSrv.dll, impacting Trend Micro's ServerProtect for Windows prior to Security Patch 4 for version 5.58. This flaw allows remote attackers to exploit a specific integer field in a request packet directed at TCP port 5168, leading to a heap-based buffer overflow. Successful exploitation can enable an attacker to execute arbitrary code on the vulnerable system, potentially compromising its integrity and confidentiality.

References

EPSS Score

39% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.