← Vulnerability feed

Vulnerability record · CVE-2006-1381 · published 24 March 2006

CVE-2006-1381: Trend micro officescan vulnerability

Trend Micro · Officescan

Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.

10.0 CVSS 2.0 High EPSS 1.6% · top 24.9%
10.0CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-1381 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3865Trend micro internet security 2007 memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC…EPSS 6.4%10.0CVE-2008-3862Trend micro officescan memory buffer overflow vulnerabilityStack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 …EPSS 18%10.0CVE-2008-4402Trend micro officescan memory buffer overflow vulnerabilityMultiple buffer overflows in CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allo…EPSS 5.5%10.0CVE-2008-2437Trend micro client-server-messaging security memory buffer overflow vulnerabilityStack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Cli…EPSS 6.7%10.0CVE-2007-3454Trend micro officescan memory buffer overflow vulnerabilityStack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute ar…EPSS 5.5%10.0CVE-2007-3455Trend micro officescan permissions and access controls vulnerabilitycgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and g…EPSS 3.0%9.3CVE-2008-3364Trend micro officescan memory buffer overflow vulnerabilityBuffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-D…EPSS 33%9.3CVE-2007-0851Trend micro client-server-messaging suite smb vulnerabilityBuffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Cent…EPSS 8.4%

Source: NIST National Vulnerability Database (record CVE-2006-1381), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.