CVE-2008-3866
21.01.2009, 20:30
The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.Enginsight
Vendor | Product | Version |
---|---|---|
trend_micro | internet_security_2007 | * |
trend_micro | internet_security_2008 | 17.0.1224 |
trend_micro | officescan | 8.0:sp1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References