← Vulnerability feed

Vulnerability record · CVE-2008-2437 · published 16 September 2008

CVE-2008-2437: Trend micro client-server-messaging security memory buffer overflow vulnerability

Trend Micro · Client Server Messaging Security

Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long ComputerName parameter.

10.0 CVSS 2.0 High EPSS 6.7% · top 6.3% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
6.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long ComputerName parameter.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/31342 Vendor Advisory
http://secunia.com/secunia_research/2008-35/ Vendor Advisory
http://securityreason.com/securityalert/4263
http://www.securityfocus.com/archive/1/496281/100/0/threaded
http://www.securityfocus.com/bid/31139 Patch
http://www.securitytracker.com/id?1020860
http://www.trendmicro.com/ftp/documentation/readme/CSM_3.6_OSCE_7.6_Win_EN_CriticalPatch_B1195_readme.txt
http://www.trendmicro.com/ftp/documentation/readme/OSCE_7.3_Win_EN_CriticalPatch_B1367_readme.txt
http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Patch1_Win_EN_CriticalPatch_B3060_readme.txt
http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Win_EN_CriticalPatch_B2424_readme.txt
http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_Win_EN_CriticalPatch_B1361_readme.txt
http://www.vupen.com/english/advisories/2008/2555
https://exchange.xforce.ibmcloud.com/vulnerabilities/45072
http://secunia.com/advisories/31342 Vendor Advisory
http://secunia.com/secunia_research/2008-35/ Vendor Advisory
http://securityreason.com/securityalert/4263
http://www.securityfocus.com/archive/1/496281/100/0/threaded
http://www.securityfocus.com/bid/31139 Patch
http://www.securitytracker.com/id?1020860
http://www.trendmicro.com/ftp/documentation/readme/CSM_3.6_OSCE_7.6_Win_EN_CriticalPatch_B1195_readme.txt
http://www.trendmicro.com/ftp/documentation/readme/OSCE_7.3_Win_EN_CriticalPatch_B1367_readme.txt
http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Patch1_Win_EN_CriticalPatch_B3060_readme.txt
http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Win_EN_CriticalPatch_B2424_readme.txt
http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_Win_EN_CriticalPatch_B1361_readme.txt
http://www.vupen.com/english/advisories/2008/2555
https://exchange.xforce.ibmcloud.com/vulnerabilities/45072

Track CVE-2008-2437 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3865Trend micro internet security 2007 memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC…EPSS 6.4%10.0CVE-2008-3862Trend micro officescan memory buffer overflow vulnerabilityStack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 …EPSS 18%10.0CVE-2008-4402Trend micro officescan memory buffer overflow vulnerabilityMultiple buffer overflows in CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allo…EPSS 5.5%10.0CVE-2007-3454Trend micro officescan memory buffer overflow vulnerabilityStack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute ar…EPSS 5.5%10.0CVE-2007-3455Trend micro officescan permissions and access controls vulnerabilitycgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and g…EPSS 3.0%10.0CVE-2006-1381Trend micro officescan vulnerabilityTrend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM p…EPSS 1.6%9.3CVE-2008-3364Trend micro officescan memory buffer overflow vulnerabilityBuffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-D…EPSS 33%9.3CVE-2007-0325Trend micro client-server-messaging security memory buffer overflow vulnerabilityMultiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan …EPSS 35%

Source: NIST National Vulnerability Database (record CVE-2008-2437), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.