Trend Micro Scan Engine Tmxpflt.sys Privilege Escalation Vulnerability
Secunia Advisory: SA27378
Release Date: 2007-10-26
Popularity: 8,394 views

Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

Software:Trend Micro Anti-Spyware 3.x
Trend Micro Anti-Spyware for Enterprise 3.x
Trend Micro Anti-Spyware for SMB 3.x
Trend Micro Client Server Messaging Security for SMB 2.x
Trend Micro Client Server Messaging Security for SMB 3.x
Trend Micro Client Server Security 3.x
Trend Micro InterScan Messaging Security Suite 5.x
Trend Micro InterScan VirusWall 3.x
Trend Micro InterScan Web Security Suite 1.x
Trend Micro InterScan Web Security Suite 2.x
Trend Micro InterScan WebProtect for ISA 3.x
Trend Micro OfficeScan Corporate Edition 3.x
Trend Micro OfficeScan Corporate Edition 5.x
Trend Micro OfficeScan Corporate Edition 6.x
Trend Micro OfficeScan Corporate Edition 7.x
Trend Micro OfficeScan Corporate Edition 8.x
Trend Micro PC-cillin 2000
Trend Micro PC-cillin 2002
Trend Micro PC-cillin 2003
Trend Micro PC-cillin for Wireless 3.x
Trend Micro PC-cillin Internet Security 2005
Trend Micro PC-cillin Internet Security 2006 / 14.x
Trend Micro PC-cillin Internet Security 2007
Trend Micro ScanMail for Lotus Notes 2.x
Trend Micro ScanMail for Lotus Notes 3.x
Trend Micro ScanMail for Microsoft Exchange 3.x
Trend Micro ScanMail for Microsoft Exchange 6.x
Trend Micro ScanMail for Microsoft Exchange 7.x
Trend Micro ServerProtect for EMC Celerra 5.x
Trend Micro ServerProtect for Windows/NetWare 5.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2007-4277


Description:
A vulnerability has been reported in Trend Micro's Scan Engine, which can be exploited by malicious, local users to gain escalated privileges.

A boundary error within the 0xa0284403 IOCTL handler of Tmxpflt.sys and insecure permissions on the "\\.\Tmfilter" DOS device interface can be exploited e.g. to cause a buffer overflow via overly long arguments passed to the affected IOCTL handler.

Successful exploitation allows execution of arbitrary code with kernel privileges.

The vulnerability affects all products using the Scan Engine Filter.

Solution:
Update to Scan Engine 8.550-1001 (available via ActiveUpdate servers on October 30, 2007).

Provided and/or discovered by:
Rubén Santamarta, reported via iDefense Labs.

Original Advisory:
Trend Micro:
http://esupport.trendmicro.com/support/viewxml.do?ContentID=1035793

iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=609


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 45 views
2. 3Com Wireless 8760 Access Point HTTP Request Processing Denial of Service // 34 views
3. Zeroboard Two Vulnerabilities // 31 views
4. VLC Media Player Multiple Vulnerabilities // 29 views
5. Zeroboard Multiple Vulnerabilities // 28 views
6. Drupal Content Construction Kit Script Insertion Vulnerabilities // 26 views
7. Cisco ASA and PIX Security Appliances Multiple Vulnerabilities // 26 views
8. Cisco Secure ACS EAP Packet Denial of Service // 26 views
9. Opera Multiple Vulnerabilities // 23 views
10. ClamAV CHM Processing Denial of Service // 22 views