peter bassill · operator
$ cve CVE-2007-1070 JSON

CVE-2007-1070 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 73% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS72.98% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2007-02-21
Last modified2026-06-16

Affected (6)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows nt
microsoftwindows vista
microsoftwindows xp
trend microserverprotect

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD