Trend Micro Control Manager CmdProcessor.exe Remote Buffer Overflow

High Nessus Plugin ID 57062


The remote Windows host contains a web application that allows remote code execution.


The Trend Micro Control Manager install on the remote Windows host is missing Critical Patch 1613. As such, the included CmdProcessor.exe component is affected by a remote stack-based buffer overflow vulnerability in the 'CGenericScheduler::AddTask' function of cmdHandlerRedAlertController.dll. By sending a specially crafted IPC packet to the service, which listens by default on TCP port 20101, an unauthenticated, remote attacker could leverage this issue to execute arbitrary code in the context of the user under which the service runs, which is SYSTEM by default.


Upgrade to Trend Micro Control Manager 5.5 if necessary and apply Critical Patch 1613.

See Also

Plugin Details

Severity: High

ID: 57062

File Name: tmcm_cmdprocessor_addtask_bof.nasl

Version: $Revision: 1.14 $

Type: local

Agent: windows

Family: Windows

Published: 2011/12/09

Modified: 2016/11/23

Dependencies: 13855

Risk Information

Risk Factor: High


Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2011/11/10

Vulnerability Publication Date: 2011/11/10

Exploitable With

Core Impact

Metasploit (TrendMicro Control Manger CmdProcessor.exe Stack Buffer Overflow)

Reference Information

CVE: CVE-2011-5001

BID: 50965

OSVDB: 77585

EDB-ID: 18514