← Vulnerability feed

Vulnerability record · CVE-2007-2508 · published 8 May 2007

CVE-2007-2508: Trend Micro ServerProtect stack buffer overflow via RPC ports

Trend Micro · Serverprotect

Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 contains multiple stack-based buffer overflows reachable through TmRpcSrv.dll. Crafted data sent to TCP port 5168 overflows CAgRpcClient::CreateBinding in AgRpcCln.dll within SpntSvc.exe, and crafted data to TCP port 3628 overflows EarthAgent.exe. Both flaws allow remote code execution on the affected server.

10.0 CVSS 2.0 High EPSS 77% · top 0.5% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with no authentication or user interaction, remote code execution, and a high EPSS score make this an urgent patch-and-isolate case.

What it is

Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 contains multiple stack-based buffer overflows reachable through TmRpcSrv.dll. Crafted data sent to TCP port 5168 overflows CAgRpcClient::CreateBinding in AgRpcCln.dll within SpntSvc.exe, and crafted data to TCP port 3628 overflows EarthAgent.exe. Both flaws allow remote code execution on the affected server.

Impact

A remote attacker can execute arbitrary code with the privileges of the affected service, typically SYSTEM on the ServerProtect host. This gives full control of the server, including the ability to disable protection or pivot into the managed network.

Attack surface

The flaws are reached over the network via TCP ports 5168 and 3628; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host that can reach those ports on a vulnerable ServerProtect installation can trigger the overflow.

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.77194 (99.5th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.

What to do

  • Apply Trend Micro ServerProtect Security Patch 2 Build 1174 or later immediately.
  • Block inbound TCP 5168 and 3628 from untrusted networks at the host and network firewall.
  • Restrict ServerProtect management and agent traffic to trusted management subnets only.
  • If patching cannot be done at once, isolate affected servers or disable the vulnerable services until the patch is applied.
  • Monitor vendor advisories for any follow-up patches or updated guidance.

Detection

  • Alert on network connections to TCP 5168 or 3628 from hosts outside the expected management subnet.
  • Inspect ServerProtect and EarthAgent process logs for crashes or abnormal termination around RPC activity.
  • Use IDS/IPS signatures for oversized or malformed RPC payloads targeting these ports.
  • Hunt for unexpected child processes or command shells spawned by SpntSvc.exe or EarthAgent.exe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://osvdb.org/35789
http://osvdb.org/35790
http://secunia.com/advisories/25186 PatchVendor Advisory
http://securitytracker.com/id?1018010 Patch
http://www.kb.cert.org/vuls/id/488424 US Government Resource
http://www.kb.cert.org/vuls/id/515616 US Government Resource
http://www.securityfocus.com/archive/1/467932/100/0/threaded
http://www.securityfocus.com/archive/1/467933/100/0/threaded
http://www.securityfocus.com/bid/23866 Exploit
http://www.securityfocus.com/bid/23868
http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch2_readme.txt PatchVendor Advisory
http://www.vupen.com/english/advisories/2007/1689 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-024.html Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-025.html Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34162
https://exchange.xforce.ibmcloud.com/vulnerabilities/34163
http://osvdb.org/35789
http://osvdb.org/35790
http://secunia.com/advisories/25186 PatchVendor Advisory
http://securitytracker.com/id?1018010 Patch
http://www.kb.cert.org/vuls/id/488424 US Government Resource
http://www.kb.cert.org/vuls/id/515616 US Government Resource
http://www.securityfocus.com/archive/1/467932/100/0/threaded
http://www.securityfocus.com/archive/1/467933/100/0/threaded
http://www.securityfocus.com/bid/23866 Exploit
http://www.securityfocus.com/bid/23868
http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch2_readme.txt PatchVendor Advisory
http://www.vupen.com/english/advisories/2007/1689 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-024.html Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-025.html Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34162
https://exchange.xforce.ibmcloud.com/vulnerabilities/34163

Track CVE-2007-2508 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-5268Trend micro serverprotect improper authentication vulnerabilityUnspecified vulnerability in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via vectors related to obtainin…EPSS 7.2%10.0CVE-2006-5269Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 8.6%10.0CVE-2007-0072Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 8.6%10.0CVE-2007-0073Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 8.6%10.0CVE-2007-0074Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 8.6%10.0CVE-2008-0012Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 6.7%10.0CVE-2008-0013Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 6.7%10.0CVE-2008-0014Trend micro serverprotect memory buffer overflow vulnerabilityHeap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code vi…EPSS 6.7%

Source: NIST National Vulnerability Database (record CVE-2007-2508), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.