Trend Micro ServerProtect earthagent.exe buffer overflow (MSRPC_TrendMicro_Suspicious_Call)

About this signature or vulnerability

Proventia Network IPS, Proventia Desktop, Proventia Server IPS for Linux technology, BlackICE PC Protection, RealSecure Network, RealSecure Server Sensor, Proventia-G 1.1 and earlier, Proventia Network IDS, IBM Security Server Protection for Windows, BlackICE Server Protection, Proventia Network MFS, Virtual Server Protection for Vmware:

This audit signature detects an MSRPC request to the following TrendMicro functions: DoHotFix, 0x1f0045 ENG_GetNotAllowToWriteFolder, 0x3002A ENG_GetVirusScanExceptionFolder, 0x30024 ENG_GetVirusScanExceptionFile, 0x30027 Locally controlled resources on the server can lead to a buffer overflow, however, it cannot be explicitly detected on the network.


Default risk level

High risk vulnerability  High

Sensors that have this signature

Proventia Network IPS: XPU 27.110, Proventia Desktop: 2120, Proventia Server IPS for Linux technology: 27.110, BlackICE PC Protection: 3.6cqr, RealSecure Network: XPU 27.110, RealSecure Server Sensor: XPU 27.110, Proventia-G 1.1 and earlier: XPU 27.110, Proventia Network IDS: XPU 27.110, IBM Security Server Protection for Windows: 1.0.914.2120, BlackICE Server Protection: 3.6.cqr, Proventia Network MFS: XPU 27.110, IBM Security Server Protection for Windows: 2.1.14.2400, Virtual Server Protection for Vmware: 1.0

Systems affected

Trend Micro ServerProtect for Windows: 5.58 Build 1176 and prior

Type

Unauthorized Access Attempt

Vulnerability description

Trend Micro ServerProtect is vulnerable to multiple buffer overflows, caused by improper bounds checking by the RPCFN_EVENTBACK_DoHotFix and CMD_CHANGE_AGENT_REGISTER_INFO functions in the earthagent.exe service. By sending a specially-crafted RPC request, a remote attacker could overflow a buffer and execute arbitrary code on the system with SYSTEM privileges or cause the application to crash.

How to remove this vulnerability

Apply the patch for this vulnerability (Security Patch 4 - Build 1185), available from the Trend Micro Web site. See References.

References

Trend Micro Web site
Product Updates
http://www.trendmicro.com/download_beta/product.asp?productid=17

ISS X-Force
Trend Micro ServerProtect earthagent.exe buffer overflow
http://www.iss.net/security_center/static/36181.php

CVE
CVE-2007-4490
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4490