CVE-2007-2508
Title: Trend Micro Serverprotect RCE
Memory Corruption
Proof Of Concept
PoC Available for CVE-2007-2508
CWE Category
CWE-119
Published Date
May 08, 2007
Modified Date
Jun 16, 2026
Exploit Status
Available
Score
10.0
CVSS v2.0
Exploit Probability (EPSS)
77.19%
Vulnerability Summary
CVE-2007-2508: Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.
Impacted Vendors
Reference Links
http://osvdb.org/35789
http://osvdb.org/35790
http://secunia.com/advisories/25186
http://securitytracker.com/id?1018010
http://www.kb.cert.org/vuls/id/488424
http://www.kb.cert.org/vuls/id/515616
http://www.securityfocus.com/archive/1/467932/100/0/threaded
http://www.securityfocus.com/archive/1/467933/100/0/threaded
http://www.securityfocus.com/bid/23866
http://www.securityfocus.com/bid/23868
http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch2_readme.txt
http://www.vupen.com/english/advisories/2007/1689
http://www.zerodayinitiative.com/advisories/ZDI-07-024.html
http://www.zerodayinitiative.com/advisories/ZDI-07-025.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/34162
https://exchange.xforce.ibmcloud.com/vulnerabilities/34163
http://osvdb.org/35789
http://osvdb.org/35790
http://secunia.com/advisories/25186
http://securitytracker.com/id?1018010
http://www.kb.cert.org/vuls/id/488424
http://www.kb.cert.org/vuls/id/515616
http://www.securityfocus.com/archive/1/467932/100/0/threaded
http://www.securityfocus.com/archive/1/467933/100/0/threaded
http://www.securityfocus.com/bid/23866
http://www.securityfocus.com/bid/23868
http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch2_readme.txt
http://www.vupen.com/english/advisories/2007/1689
http://www.zerodayinitiative.com/advisories/ZDI-07-024.html
http://www.zerodayinitiative.com/advisories/ZDI-07-025.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/34162
https://exchange.xforce.ibmcloud.com/vulnerabilities/34163
CVSS v2.0
Source Entity
[email protected]
Severity
HIGH
10.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:C/I:C/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2007-2508 Exploits & PoCs (Proof Of Concept)
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Stack
No specific products linked.