Integer Overflow Vulnerability in Trend Micro ServerProtect for Windows
CVE-2007-4219
Currently unrated
Summary
An integer overflow vulnerability exists within the RPCFN_SYNC_TASK function in StRpcSrv.dll, impacting Trend Micro's ServerProtect for Windows prior to Security Patch 4 for version 5.58. This flaw allows remote attackers to exploit a specific integer field in a request packet directed at TCP port 5168, leading to a heap-based buffer overflow. Successful exploitation can enable an attacker to execute arbitrary code on the vulnerable system, potentially compromising its integrity and confidentiality.
References
EPSS Score
39% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved