← Vulnerability feed

Vulnerability record · CVE-2008-1365 · published 17 March 2008

CVE-2008-1365: Trend Micro OfficeScan stack buffer overflow via long encrypted password

Trend Micro · Officescan Corporate Edition

Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, contain a stack-based buffer overflow triggered by a long encrypted password. The flaw is reachable remotely through components including cgiChkMasterPwd.exe and policyserver.exe via cgiABLogon.exe, and can lead to arbitrary code execution or a crash.

6.4 CVSS 2.0 Medium EPSS 51% · top 1.1% CWE-119 · Memory buffer overflow
6.4CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1) cgiChkMasterPwd.exe, (2) policyserver.exe as reachable through cgiABLogon.exe, and other vectors.

AV:N/AC:L/Au:N/C:N/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with a public exploit reference and very high EPSS probability, though the CVSS 2.0 base score is only 6.4 and KEV listing is absent.

What it is

Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, contain a stack-based buffer overflow triggered by a long encrypted password. The flaw is reachable remotely through components including cgiChkMasterPwd.exe and policyserver.exe via cgiABLogon.exe, and can lead to arbitrary code execution or a crash.

Impact

A remote attacker can execute arbitrary code in the context of the affected service or cause a denial of service by crashing the process. The CVSS 2.0 vector shows no confidentiality impact but partial integrity and availability impact.

Attack surface

The vulnerability is network-reachable (AV:N) with low attack complexity and no authentication required (Au:N), based on the CVSS vector and the description of remote reachability through the listed executables. No user interaction is indicated.

Exploitation

An exploit reference is tagged in the public references, and EPSS shows a high 30-day probability (0.51111, 98.879th percentile), but the CVE is not listed in CISA KEV and no ransomware usage is documented.

What to do

  • Upgrade OfficeScan Corporate Edition to a version later than 8.0 Patch 2 build 1189 or 7.3 Patch 3 build 1314, or apply the vendor patch referenced in the Secunia advisory.
  • Restrict network access to the OfficeScan management and CGI endpoints (cgiChkMasterPwd.exe, cgiABLogon.exe, policyserver.exe) to trusted management hosts only.
  • If immediate patching is not possible, place the affected services behind a reverse proxy or WAF rule that rejects oversized password parameters.
  • Monitor vendor advisories for updated builds and confirm the installed build number against the affected ranges.

Detection

  • Inspect web and application logs for requests to cgiChkMasterPwd.exe or cgiABLogon.exe containing unusually long password parameters.
  • Monitor for crashes or abnormal process termination of cgiChkMasterPwd.exe, cgiABLogon.exe, or policyserver.exe.
  • Use network IDS signatures for oversized encrypted password fields directed at OfficeScan CGI endpoints.
  • Alert on unexpected child processes or command execution originating from the OfficeScan service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1365 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2007-0325Trend micro client-server-messaging security memory buffer overflow vulnerabilityMultiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan …EPSS 35%6.4CVE-2006-5211Trend micro officescan corporate edition vulnerabilityTrend Micro OfficeScan 6.0 in Client/Server/Messaging (CSM) Suite for SMB 2.0 before 6.0.0.1385, and OfficeScan Corporate Edition (OSCE) 6.5 before 6…EPSS 2.7%5.0CVE-2008-1366Trend micro officescan corporate edition improper input validation vulnerabilityTrend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to cause…EPSS 2.2%9.5CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1365), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.