HomeTrend MicroCVE-2007-4277

CVE-2007-4277

UNKNOWN
6.6CVSS
Published: 2007-10-30
Updated: 2025-04-09
AI Analysis

Description

The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.500.0.1002, has weak permissions (Everyone:Write) for the \\.\Tmfilter device, which allows local users to send arbitrary content to the device via the IOCTL functionality. NOTE: this can be leveraged for privilege escalation by exploiting a buffer overflow in the handler for IOCTL 0xa0284403.

CVSS Metrics

Vector
AV:L/AC:L/Au:N/C:N/I:C/A:C
Access Vector
local
Access Cmplx
low
Auth
none
Confidentiality
none
Integrity
complete
Availability
complete
Weaknesses
CWE-119CWE-264

Metadata

Primary Vendor
TREND_MICRO
Published
10/30/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

trend_micro : pc-cillin_internet_security_2007trend_micro : scan_engine

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2007-4277 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com