CVE-2007-6507

Trend Micro ServerProtect <5.58 - RCE

Title source: llm

Description

SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.dll in the DCE/RPC interface, which allows remote attackers to obtain "full file system access" and execute arbitrary code.

Exploits (1)

metasploit WORKING POC
by toto · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/serverprotect/file.rb

Scores

EPSS 0.7136
EPSS Percentile 98.7%

Details

CWE
CWE-264
Status published
Products (1)
trend_micro/serverprotect 5.58_security_patch_3
Published Dec 20, 2007
Tracked Since Feb 18, 2026