Vulnerability record · CVE-2008-1365 · published 17 March 2008
CVE-2008-1365: Trend Micro OfficeScan stack buffer overflow via long encrypted password
Trend Micro · Officescan Corporate Edition
Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, contain a stack-based buffer overflow triggered by a long encrypted password. The flaw is reachable remotely through components including cgiChkMasterPwd.exe and policyserver.exe via cgiABLogon.exe, and can lead to arbitrary code execution or a crash.
Description
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1) cgiChkMasterPwd.exe, (2) policyserver.exe as reachable through cgiABLogon.exe, and other vectors.
AV:N/AC:L/Au:N/C:N/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a public exploit reference and very high EPSS probability, though the CVSS 2.0 base score is only 6.4 and KEV listing is absent.
What it is
Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, contain a stack-based buffer overflow triggered by a long encrypted password. The flaw is reachable remotely through components including cgiChkMasterPwd.exe and policyserver.exe via cgiABLogon.exe, and can lead to arbitrary code execution or a crash.
Impact
A remote attacker can execute arbitrary code in the context of the affected service or cause a denial of service by crashing the process. The CVSS 2.0 vector shows no confidentiality impact but partial integrity and availability impact.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no authentication required (Au:N), based on the CVSS vector and the description of remote reachability through the listed executables. No user interaction is indicated.
Exploitation
An exploit reference is tagged in the public references, and EPSS shows a high 30-day probability (0.51111, 98.879th percentile), but the CVE is not listed in CISA KEV and no ransomware usage is documented.
What to do
- Upgrade OfficeScan Corporate Edition to a version later than 8.0 Patch 2 build 1189 or 7.3 Patch 3 build 1314, or apply the vendor patch referenced in the Secunia advisory.
- Restrict network access to the OfficeScan management and CGI endpoints (cgiChkMasterPwd.exe, cgiABLogon.exe, policyserver.exe) to trusted management hosts only.
- If immediate patching is not possible, place the affected services behind a reverse proxy or WAF rule that rejects oversized password parameters.
- Monitor vendor advisories for updated builds and confirm the installed build number against the affected ranges.
Detection
- Inspect web and application logs for requests to cgiChkMasterPwd.exe or cgiABLogon.exe containing unusually long password parameters.
- Monitor for crashes or abnormal process termination of cgiChkMasterPwd.exe, cgiABLogon.exe, or policyserver.exe.
- Use network IDS signatures for oversized encrypted password fields directed at OfficeScan CGI endpoints.
- Alert on unexpected child processes or command execution originating from the OfficeScan service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1365 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1365), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.