CVE-2011-5001
Trend Micro Control Manager < 5.5 - Remote Code Execution via Crafted IPC Packet
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2011-5001.
PoCs published by Metasploit, Luigi Auriemma, Blue, including Metasploit module exploits/windows/misc/trendmicro_cmdprocessor_addtask.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in TrendMicro Control Manager's CmdProcessor.exe via a crafted IPC packet sent to TCP port 20101. It uses ROP techniques to bypass DEP and achieve remote code execution.
Description
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.
Exploits (2)
This Metasploit module exploits a stack-based buffer overflow in TrendMicro Control Manager's CmdProcessor.exe via a crafted IPC packet sent to TCP port 20101. It uses ROP techniques to bypass DEP and achieve remote code execution.
This Metasploit module exploits a stack buffer overflow in TrendMicro Control Manager's CmdProcessor.exe via a crafted IPC packet sent to TCP port 20101. It leverages a ROP chain to bypass DEP and execute arbitrary code under the context of the user.