← Back

CVE-2007-4277

nvd nist
Published: Oct 30, 2007Modified: Apr 23, 2026

JSON object

Loading...
6.6
Vector
AV:L/AC:L/Au:N/C:N/I:C/A:C
Exploitability: 3.9 / Impact: 9.2
Source: NVD

Description

The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.500.0.1002, has weak permissions (Everyone:Write) for the \\.\Tmfilter device, which allows local users to send arbitrary content to the device via the IOCTL functionality. NOTE: this can be leveraged for privilege escalation by exploiting a buffer overflow in the handler for IOCTL 0xa0284403.

Affected (2)

2 products
Pc Cillin Internet Security 2007
Scan Engine
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Up to 8.500

References (14)

Timeline

No history available yet.