CVE-2007-1070
EXPLOITEDTrend Micro ServerProtect for Windows & EMC 5.58-5.62 - RCE
Title source: llmExploitation Summary
CVE-2007-1070 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 3 public exploits from researchers including Metasploit, devcode, MC, including a Metasploit module exploits/windows/antivirus/trendmicro_serverprotect.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in Trend Micro ServerProtect 5.58 via a crafted RPC request to execute arbitrary code. It uses a known return address in StCommon.dll to achieve remote code execution.
Description
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.
Exploits (3)
This Metasploit module exploits a buffer overflow in Trend Micro ServerProtect 5.58 via a crafted RPC request to execute arbitrary code. It uses a known return address in StCommon.dll to achieve remote code execution.
This exploit targets a stack-based buffer overflow in Trend Micro ServerProtect's eng50.dll via a crafted RPC request to SpntSvc.exe. It sends a DCE bind packet followed by a malicious payload containing shellcode to achieve remote code execution.
This Metasploit module exploits a buffer overflow in Trend Micro ServerProtect 5.58 via a crafted DCERPC request to execute arbitrary code. It targets a specific return address in StCommon.dll and includes a payload encoder to avoid bad characters.