← back
CVE-2007-2508

CVE-2007-2508

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 77%
from disclosure to weapon0 days
Published on NVDMay 8
1st PoCMay 7
metasploitMay 7
exploitation probability
77%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.