Vulnerability record · CVE-2011-5001 · published 25 December 2011
CVE-2011-5001: Trend Micro Control Manager IPC packet stack buffer overflow
Trend Micro · Control Manager
CVE-2011-5001 is a stack-based buffer overflow in the CGenericScheduler::AddTask function of cmdHandlerRedAlertController.dll, loaded by CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613. A crafted IPC packet sent to TCP port 20101 can overwrite stack memory, and because the flaw is remotely reachable without authentication, it is a serious pre-auth code execution risk for exposed management servers.
Description
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 base score of 10 and high EPSS probability makes this a top-priority patch for any exposed Control Manager 5.5 deployment.
What it is
CVE-2011-5001 is a stack-based buffer overflow in the CGenericScheduler::AddTask function of cmdHandlerRedAlertController.dll, loaded by CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613. A crafted IPC packet sent to TCP port 20101 can overwrite stack memory, and because the flaw is remotely reachable without authentication, it is a serious pre-auth code execution risk for exposed management servers.
Impact
A remote attacker can execute arbitrary code in the context of the CmdProcessor.exe process, which typically runs with service-level privileges on the Control Manager host. That gives full control of the management server and a foothold into the systems it administers.
Attack surface
The flaw is reached over the network by sending a crafted IPC packet to TCP port 20101, per the description and the AV:N/AC:L/Au:N/C:C/I:C/A:C vector. No authentication or user interaction is required.
Exploitation
The record shows no CISA KEV listing and no reference tagged as exploit code, but EPSS is high at 0.64363 (99.2nd percentile), indicating elevated likelihood of attempted exploitation. No public exploit details are confirmed in the supplied references.
What to do
- Upgrade Control Manager 5.5 to Build 1613 or later using the vendor critical patch readme.
- Restrict network access to TCP port 20101 to trusted management hosts only; do not expose it to untrusted networks.
- Segment the Control Manager server from general user networks and limit its administrative reach.
- Monitor vendor advisories for this product line and apply subsequent patches promptly.
Detection
- Alert on unexpected inbound connections to TCP port 20101 from hosts outside the management network.
- Monitor CmdProcessor.exe for crashes or abnormal process termination that could indicate a failed overflow attempt.
- Watch for suspicious child processes or network connections originating from the Control Manager server after IPC traffic.
- Review logs for malformed or oversized IPC packets targeting the Control Manager service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-5001 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-5001), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.