CVE-2007-0856

UnknownEPSS 0.95%

Last modified

CVE-2007-0856 is a vulnerability of currently unknown severity. TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.. EPSS estimates a 0.95% chance of exploitation in the next 30 days.

Description

TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.

Metrics

EPSS Probability
0.95%

56.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Trend MicroClient-Server-Messaging Security3.5
Trend MicroDamage Cleanup Services3.2
Trend MicroPc-Cillin Internet Security2007
Trend MicroTmcomm.Sys1.5.1052
Trend MicroTrend Micro Antirootkit Common ModuleAll versions
Trend MicroTrend Micro Antispyware3.0_sp2
Trend MicroTrend Micro Antispyware3.2_sp1
Trend MicroTrend Micro Antispyware3.5
Trend MicroTrend Micro Antivirus2007
Trend MicroVsapini.Sys3.320.1003

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-0856?
TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.
How severe is CVE-2007-0856?
Severity scoring for CVE-2007-0856 is pending analysis. The EPSS model estimates a 0.95% probability of exploitation in the next 30 days.
How do I fix CVE-2007-0856?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-0856?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST