Proventia Network IPS, Proventia Desktop, Proventia Server IPS for Linux technology, BlackICE PC Protection, RealSecure Network, RealSecure Server Sensor, Proventia-G 1.1 and earlier, Proventia Network IDS, IBM Security Server Protection for Windows, BlackICE Server Protection, Proventia Network MFS, Virtual Server Protection for Vmware:
This audit signature detects an MSRPC request to the following TrendMicro functions: DoHotFix, 0x1f0045 ENG_GetNotAllowToWriteFolder, 0x3002A ENG_GetVirusScanExceptionFolder, 0x30024 ENG_GetVirusScanExceptionFile, 0x30027 Locally controlled resources on the server can lead to a buffer overflow, however, it cannot be explicitly detected on the network.
High
Proventia Network IPS: XPU 27.110, Proventia Desktop: 2120, Proventia Server IPS for Linux technology: 27.110, BlackICE PC Protection: 3.6cqr, RealSecure Network: XPU 27.110, RealSecure Server Sensor: XPU 27.110, Proventia-G 1.1 and earlier: XPU 27.110, Proventia Network IDS: XPU 27.110, IBM Security Server Protection for Windows: 1.0.914.2120, BlackICE Server Protection: 3.6.cqr, Proventia Network MFS: XPU 27.110, IBM Security Server Protection for Windows: 2.1.14.2400, Virtual Server Protection for Vmware: 1.0
Trend Micro ServerProtect for Windows: 5.58 Build 1176 and prior
Unauthorized Access Attempt
Trend Micro ServerProtect is vulnerable to multiple buffer overflows, caused by improper bounds checking by the RPCFN_EVENTBACK_DoHotFix and CMD_CHANGE_AGENT_REGISTER_INFO functions in the earthagent.exe service. By sending a specially-crafted RPC request, a remote attacker could overflow a buffer and execute arbitrary code on the system with SYSTEM privileges or cause the application to crash.
Apply the patch for this vulnerability (Security Patch 4 - Build 1185), available from the Trend Micro Web site. See References.
Trend Micro Web site
Product Updates
http://www.trendmicro.com/download_beta/product.asp?productid=17
ISS X-Force
Trend Micro ServerProtect earthagent.exe buffer overflow
http://www.iss.net/security_center/static/36181.php
CVE
CVE-2007-4490
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4490