← Vulnerability feed

Vulnerability record · CVE-2007-1070 · published 21 February 2007

CVE-2007-1070: Trend Micro ServerProtect RPC stack buffer overflows allow remote code execution

Trend Micro · Serverprotect

Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, contain multiple stack-based buffer overflows in TmRpcSrv.dll. Crafted RPC requests trigger overflows in the CMON_NetTestConnection, CMON_ActiveUpdate, and CMON_ActiveRollback functions in StCommon.dll, and in the ENG_SetRealTimeScanConfigInfo and ENG_SendEMail functions in eng50.dll. The flaw matters because it is remotely reachable without authentication and can lead to arbitrary code execution on the affected server.

10.0 CVSS 2.0 High EPSS 73% · top 0.6%
10.0CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score is 10.0 with a network-reachable, unauthenticated vector that allows complete compromise, and EPSS is above the 99th percentile.

What it is

Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, contain multiple stack-based buffer overflows in TmRpcSrv.dll. Crafted RPC requests trigger overflows in the CMON_NetTestConnection, CMON_ActiveUpdate, and CMON_ActiveRollback functions in StCommon.dll, and in the ENG_SetRealTimeScanConfigInfo and ENG_SendEMail functions in eng50.dll. The flaw matters because it is remotely reachable without authentication and can lead to arbitrary code execution on the affected server.

Impact

A remote attacker can execute arbitrary code with the privileges of the affected service, potentially taking full control of the ServerProtect host. Given the CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C, the impact is complete compromise of confidentiality, integrity, and availability.

Attack surface

The vulnerability is reached over the network through crafted RPC requests to TmRpcSrv.dll. The CVSS vector indicates no authentication is required and no user interaction is needed.

Exploitation

The record does not list this CVE in CISA KEV and does not include an exploit tag, but EPSS is 0.71884 (99.397th percentile), indicating a high modeled likelihood of exploitation activity. No ransomware group association is documented.

What to do

  • Apply the vendor patch referenced in the Trend Micro advisory and readme for ServerProtect 5.58 and the affected EMC and Network Appliance Filer versions.
  • Restrict network access to the RPC service (TmRpcSrv.dll) to trusted management hosts only.
  • If patching is not immediately possible, isolate or disable the affected ServerProtect RPC service until the update can be applied.
  • Monitor vendor and CERT/CC advisories for updated guidance and any revised patch information.

Detection

  • Monitor network traffic and host logs for unexpected or malformed RPC requests to the ServerProtect RPC service.
  • Watch for crashes or abnormal termination of TmRpcSrv.dll, StCommon.dll, or eng50.dll on ServerProtect hosts.
  • Alert on unexpected process creation or outbound connections originating from the ServerProtect service process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290 PatchVendor Advisory
http://osvdb.org/33042
http://secunia.com/advisories/24243
http://www.kb.cert.org/vuls/id/349393 US Government Resource
http://www.kb.cert.org/vuls/id/466609 US Government Resource
http://www.kb.cert.org/vuls/id/630025 US Government Resource
http://www.kb.cert.org/vuls/id/730433 US Government Resource
http://www.securityfocus.com/archive/1/460686/100/0/threaded
http://www.securityfocus.com/archive/1/460690/100/0/threaded
http://www.securityfocus.com/bid/22639
http://www.securitytracker.com/id?1017676
http://www.tippingpoint.com/security/advisories/TSRT-07-01.html Vendor Advisory
http://www.tippingpoint.com/security/advisories/TSRT-07-02.html Vendor Advisory
http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch1_readme.txt Vendor Advisory
http://www.vupen.com/english/advisories/2007/0670
https://exchange.xforce.ibmcloud.com/vulnerabilities/32594
https://exchange.xforce.ibmcloud.com/vulnerabilities/32601
http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290 PatchVendor Advisory
http://osvdb.org/33042
http://secunia.com/advisories/24243
http://www.kb.cert.org/vuls/id/349393 US Government Resource
http://www.kb.cert.org/vuls/id/466609 US Government Resource
http://www.kb.cert.org/vuls/id/630025 US Government Resource
http://www.kb.cert.org/vuls/id/730433 US Government Resource
http://www.securityfocus.com/archive/1/460686/100/0/threaded
http://www.securityfocus.com/archive/1/460690/100/0/threaded
http://www.securityfocus.com/bid/22639
http://www.securitytracker.com/id?1017676
http://www.tippingpoint.com/security/advisories/TSRT-07-01.html Vendor Advisory
http://www.tippingpoint.com/security/advisories/TSRT-07-02.html Vendor Advisory
http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch1_readme.txt Vendor Advisory
http://www.vupen.com/english/advisories/2007/0670
https://exchange.xforce.ibmcloud.com/vulnerabilities/32594
https://exchange.xforce.ibmcloud.com/vulnerabilities/32601

Track CVE-2007-1070 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-5268Trend micro serverprotect improper authentication vulnerabilityUnspecified vulnerability in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via vectors related to obtainin…EPSS 7.2%10.0CVE-2006-5269Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 8.6%10.0CVE-2007-0072Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 8.6%10.0CVE-2007-0073Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 8.6%10.0CVE-2007-0074Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 8.6%10.0CVE-2008-0012Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 6.7%10.0CVE-2008-0013Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 6.7%10.0CVE-2008-0014Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 6.7%

Source: NIST National Vulnerability Database (record CVE-2007-1070), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.