Trend Micro ServerProtect Multiple Remote Insecure Method Exposure Vulnerabilities
BID:26912
Info
Trend Micro ServerProtect Multiple Remote Insecure Method Exposure Vulnerabilities
| Bugtraq ID: | 26912 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-6507 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Eric DETOISIEN is credited with the discovery of these issues. |
| Vulnerable: |
Trend Micro ServerProtect 5.58 (Security Patch |
| Not Vulnerable: | |
Discussion
Trend Micro ServerProtect Multiple Remote Insecure Method Exposure Vulnerabilities
Trend Micro ServerProtect is prone to multiple vulnerabilities that let remote attackers gain full access to the filesystem. The issues occur because the application fails to properly restrict access to certain DCE/RPC methods.
With full access to the filesystem, attackers may be able to execute arbitrary code with SYSTEM-level privileges and completely compromise affected computers.
These issues were reported to affect ServerProtect 5.58 (Security Patch 3). Earlier versions may also be affected.
Reports indicate that these vulnerabilities have been fixed in Security Patch 4.
UPDATE (August 14, 2008): Reports indicate that Security Patch 4 is still vulnerable, but Security Patch 5 is not.
Trend Micro ServerProtect is prone to multiple vulnerabilities that let remote attackers gain full access to the filesystem. The issues occur because the application fails to properly restrict access to certain DCE/RPC methods.
With full access to the filesystem, attackers may be able to execute arbitrary code with SYSTEM-level privileges and completely compromise affected computers.
These issues were reported to affect ServerProtect 5.58 (Security Patch 3). Earlier versions may also be affected.
Reports indicate that these vulnerabilities have been fixed in Security Patch 4.
UPDATE (August 14, 2008): Reports indicate that Security Patch 4 is still vulnerable, but Security Patch 5 is not.
Exploit / POC
Trend Micro ServerProtect Multiple Remote Insecure Method Exposure Vulnerabilities
An attacker can use standard tools to exploit these issues.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An attacker can use standard tools to exploit these issues.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Trend Micro ServerProtect Multiple Remote Insecure Method Exposure Vulnerabilities
Solution:
Reports indicate that these vulnerabilities have been fixed in Security Patch 4, but Symantec was unable to verify this information. Please contact the vendor for details.
UPDATE (August 14, 2008): Reports indicated that Security Patch 4 is still vulnerable, but security Patch 5 is not.
Solution:
Reports indicate that these vulnerabilities have been fixed in Security Patch 4, but Symantec was unable to verify this information. Please contact the vendor for details.
UPDATE (August 14, 2008): Reports indicated that Security Patch 4 is still vulnerable, but security Patch 5 is not.
References
Trend Micro ServerProtect Multiple Remote Insecure Method Exposure Vulnerabilities
References:
References:
- ServerProtect Security Patch 4 (Trend Micro)
- Trend Micro Homepage (Trend Micro)
- ZDI-07-077 - Trend Micro ServerProtect StRpcSrv.dll Insecure Method Exposure Vul (ZDI)