← Vulnerability feed

Vulnerability record · CVE-2011-5001 · published 25 December 2011

CVE-2011-5001: Trend Micro Control Manager IPC packet stack buffer overflow

Trend Micro · Control Manager

CVE-2011-5001 is a stack-based buffer overflow in the CGenericScheduler::AddTask function of cmdHandlerRedAlertController.dll, loaded by CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613. A crafted IPC packet sent to TCP port 20101 can overwrite stack memory, and because the flaw is remotely reachable without authentication, it is a serious pre-auth code execution risk for exposed management servers.

10.0 CVSS 2.0 High EPSS 64% · top 0.8% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 base score of 10 and high EPSS probability makes this a top-priority patch for any exposed Control Manager 5.5 deployment.

What it is

CVE-2011-5001 is a stack-based buffer overflow in the CGenericScheduler::AddTask function of cmdHandlerRedAlertController.dll, loaded by CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613. A crafted IPC packet sent to TCP port 20101 can overwrite stack memory, and because the flaw is remotely reachable without authentication, it is a serious pre-auth code execution risk for exposed management servers.

Impact

A remote attacker can execute arbitrary code in the context of the CmdProcessor.exe process, which typically runs with service-level privileges on the Control Manager host. That gives full control of the management server and a foothold into the systems it administers.

Attack surface

The flaw is reached over the network by sending a crafted IPC packet to TCP port 20101, per the description and the AV:N/AC:L/Au:N/C:C/I:C/A:C vector. No authentication or user interaction is required.

Exploitation

The record shows no CISA KEV listing and no reference tagged as exploit code, but EPSS is high at 0.64363 (99.2nd percentile), indicating elevated likelihood of attempted exploitation. No public exploit details are confirmed in the supplied references.

What to do

  • Upgrade Control Manager 5.5 to Build 1613 or later using the vendor critical patch readme.
  • Restrict network access to TCP port 20101 to trusted management hosts only; do not expose it to untrusted networks.
  • Segment the Control Manager server from general user networks and limit its administrative reach.
  • Monitor vendor advisories for this product line and apply subsequent patches promptly.

Detection

  • Alert on unexpected inbound connections to TCP port 20101 from hosts outside the management network.
  • Monitor CmdProcessor.exe for crashes or abnormal process termination that could indicate a failed overflow attempt.
  • Watch for suspicious child processes or network connections originating from the Control Manager server after IPC traffic.
  • Review logs for malformed or oversized IPC packets targeting the Control Manager service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-5001 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2007-0851Trend micro client-server-messaging suite smb vulnerabilityBuffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Cent…EPSS 8.4%7.5CVE-2012-2998Trend micro control manager sql injection vulnerabilitySQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remot…EPSS 6.1%7.5CVE-2005-0383Trend micro control manager vulnerabilityTrend Micro Control Manager 3.0 Enterprise Edition allows remote attackers to gain privileges via a replay attack of the encrypted username and passw…EPSS 1.7%7.5CVE-2005-0533Trend micro client-server-messaging suite smb vulnerabilityHeap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to …EPSS 4.4%4.3CVE-2006-3261Trend micro control manager vulnerabilityCross-site scripting (XSS) vulnerability in Trend Micro Control Manager (TMCM) 3.5 allows remote attackers to inject arbitrary web script or HTML via…EPSS 1.3%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2011-5001), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.