Vulnerability record · CVE-2007-1070 · published 21 February 2007
CVE-2007-1070: Trend Micro ServerProtect RPC stack buffer overflows allow remote code execution
Trend Micro · Serverprotect
Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, contain multiple stack-based buffer overflows in TmRpcSrv.dll. Crafted RPC requests trigger overflows in the CMON_NetTestConnection, CMON_ActiveUpdate, and CMON_ActiveRollback functions in StCommon.dll, and in the ENG_SetRealTimeScanConfigInfo and ENG_SendEMail functions in eng50.dll. The flaw matters because it is remotely reachable without authentication and can lead to arbitrary code execution on the affected server.
Description
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score is 10.0 with a network-reachable, unauthenticated vector that allows complete compromise, and EPSS is above the 99th percentile.
What it is
Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, contain multiple stack-based buffer overflows in TmRpcSrv.dll. Crafted RPC requests trigger overflows in the CMON_NetTestConnection, CMON_ActiveUpdate, and CMON_ActiveRollback functions in StCommon.dll, and in the ENG_SetRealTimeScanConfigInfo and ENG_SendEMail functions in eng50.dll. The flaw matters because it is remotely reachable without authentication and can lead to arbitrary code execution on the affected server.
Impact
A remote attacker can execute arbitrary code with the privileges of the affected service, potentially taking full control of the ServerProtect host. Given the CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C, the impact is complete compromise of confidentiality, integrity, and availability.
Attack surface
The vulnerability is reached over the network through crafted RPC requests to TmRpcSrv.dll. The CVSS vector indicates no authentication is required and no user interaction is needed.
Exploitation
The record does not list this CVE in CISA KEV and does not include an exploit tag, but EPSS is 0.71884 (99.397th percentile), indicating a high modeled likelihood of exploitation activity. No ransomware group association is documented.
What to do
- Apply the vendor patch referenced in the Trend Micro advisory and readme for ServerProtect 5.58 and the affected EMC and Network Appliance Filer versions.
- Restrict network access to the RPC service (TmRpcSrv.dll) to trusted management hosts only.
- If patching is not immediately possible, isolate or disable the affected ServerProtect RPC service until the update can be applied.
- Monitor vendor and CERT/CC advisories for updated guidance and any revised patch information.
Detection
- Monitor network traffic and host logs for unexpected or malformed RPC requests to the ServerProtect RPC service.
- Watch for crashes or abnormal termination of TmRpcSrv.dll, StCommon.dll, or eng50.dll on ServerProtect hosts.
- Alert on unexpected process creation or outbound connections originating from the ServerProtect service process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1070 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1070), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.