Vulnerability record · CVE-2007-2508 · published 8 May 2007
CVE-2007-2508: Trend Micro ServerProtect stack buffer overflow via RPC ports
Trend Micro · Serverprotect
Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 contains multiple stack-based buffer overflows reachable through TmRpcSrv.dll. Crafted data sent to TCP port 5168 overflows CAgRpcClient::CreateBinding in AgRpcCln.dll within SpntSvc.exe, and crafted data to TCP port 3628 overflows EarthAgent.exe. Both flaws allow remote code execution on the affected server.
Description
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with no authentication or user interaction, remote code execution, and a high EPSS score make this an urgent patch-and-isolate case.
What it is
Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 contains multiple stack-based buffer overflows reachable through TmRpcSrv.dll. Crafted data sent to TCP port 5168 overflows CAgRpcClient::CreateBinding in AgRpcCln.dll within SpntSvc.exe, and crafted data to TCP port 3628 overflows EarthAgent.exe. Both flaws allow remote code execution on the affected server.
Impact
A remote attacker can execute arbitrary code with the privileges of the affected service, typically SYSTEM on the ServerProtect host. This gives full control of the server, including the ability to disable protection or pivot into the managed network.
Attack surface
The flaws are reached over the network via TCP ports 5168 and 3628; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host that can reach those ports on a vulnerable ServerProtect installation can trigger the overflow.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.77194 (99.5th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.
What to do
- Apply Trend Micro ServerProtect Security Patch 2 Build 1174 or later immediately.
- Block inbound TCP 5168 and 3628 from untrusted networks at the host and network firewall.
- Restrict ServerProtect management and agent traffic to trusted management subnets only.
- If patching cannot be done at once, isolate affected servers or disable the vulnerable services until the patch is applied.
- Monitor vendor advisories for any follow-up patches or updated guidance.
Detection
- Alert on network connections to TCP 5168 or 3628 from hosts outside the expected management subnet.
- Inspect ServerProtect and EarthAgent process logs for crashes or abnormal termination around RPC activity.
- Use IDS/IPS signatures for oversized or malformed RPC payloads targeting these ports.
- Hunt for unexpected child processes or command shells spawned by SpntSvc.exe or EarthAgent.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2508 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2508), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.