Knowledge Base

Support

[Vulnerability Confirmation] CASProcessor.exe can be used to execute a code remotely in Trend Micro Control Manager (TMCM) using a malformed BLOB

Solution IDLast Updated
1058292Date : 2011/07/20 Time: 7:38 PM (PST)


Product/VersionPlatform
Control Manager - 3.5, 5.0, 5.5
Windows - 2003 Enterprise Server, 2003 Standard Server Edition, 2003 Standard Server Edition 64-bit, 2008 Enterprise Server, 2008 Enterprise Server Edition 64-bit, 2008 Standard Server Edition, 2008 Standard Server Edition 64-bit

Problem Description

SEG has been notified of a product vulnerability in TMCM.

 

Remote attackers are able to execute an arbitrary code on vulnerable installations of TMCM. Authentication is not required to exploit this vulnerability.

 

The specific flaw can be found in the En_Utility.dll file and on a module called CASProcessor.exe that is running on the TCP port 20801.

 

A specially crafted packet with malformed BLOB encrypted data is handled by the HandleMcpRequest(). It contains instructions that will allow for an integer wrap that leads to a heap overflow.

 

An attacker can leverage on this vulnerability to execute the code under the context of the SYSTEM.

 

The following are affected by this vulnerability:

 

·

TMCM 5.5

 

 

·

TMCM 5.0

 

This was first reported from TippingPoint Zero Day Initiative (ZDI-CAN-1139).

Solution

To resolve this, please contact Trend Micro Technical Support for the associated Critical Patch or hot fix.


Rate this Solution
Did this article help you?  
 
Please provide your comments to help us improve this solution.

 
  *This form is an automated system. General questions, technical, sales and product-related issues submitted through this form will not be answered.
 
 

Connect with us on