CVE-2008-3866
Trend Micro OfficeScan <8.0 SP1 Patch 1 - Privilege Escalation
Title source: llmDescription
The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.
References (9)
Scores
EPSS
0.0014
EPSS Percentile
34.1%
Classification
CWE
CWE-287
Status
draft
Affected Products (3)
trend_micro/internet_security_2007
trend_micro/internet_security_2008
trend_micro/officescan
Timeline
Published
Jan 21, 2009
Tracked Since
Feb 18, 2026