CVE-2008-3866
The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection…
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- trend micro/internet security 2007 · trend micro/internet security 2008 · trend micro/officescan
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/31160Patch, Vendor Advisory
- http://secunia.com/advisories/33609Patch, Vendor Advisory
- http://secunia.com/secunia_research/2008-43/Vendor Advisory
- http://www.securityfocus.com/bid/33358Patch
- http://www.securitytracker.com/id?1021616
- http://www.securitytracker.com/id?1021617
- http://www.trendmicro.com/ftp/documentation/readme/OSCE8.0_SP1_Patch1_CriticalPatch_3191_Readme.txtVendor Advisory
- http://www.vupen.com/english/advisories/2009/0191
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48108
- http://secunia.com/advisories/31160Patch, Vendor Advisory
- http://secunia.com/advisories/33609Patch, Vendor Advisory
- http://secunia.com/secunia_research/2008-43/Vendor Advisory
- http://www.securityfocus.com/bid/33358Patch
- http://www.securitytracker.com/id?1021616
- http://www.securitytracker.com/id?1021617
- http://www.trendmicro.com/ftp/documentation/readme/OSCE8.0_SP1_Patch1_CriticalPatch_3191_Readme.txtVendor Advisory
- http://www.vupen.com/english/advisories/2009/0191
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48108
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.