Internet Security Privacy Policy

Friday, August 31, 2007

Potential Trend Micro ServerProtect Security Risk

Vulnerability Identifier: CVE-2007-1070
Discovery Date: Aug 22, 2007
Related Malware: BKDR_IRCBOT.AJZ
Affected Software:

* Trend Micro ServerProtect for Microsoft Windows 5.58

Description:

Trend Micro has recently been informed by SANS Internet Storm Center (ISC) that there is an increase in scans of port 5168, which is a key communication port utilized by the Trend Micro ServerProtect software.

Trend Micro has been made aware of potential vulnerabilities in ServerProtect and has been actively working on developing patches to eliminate these vulnerabilities. This sudden increase in scanning traffic could indicate that malicious entities may be looking for ways to exploit vulnerable machines.

To our knowledge, there are no confirmed exploits of this vulnerability to date. Nevertheless, we implore security administrators to apply the latest ServerProtect security patch available from Trend Micro as soon as possible to protect against any potential attack.

Patch Information:

The latest security patches and ReadMe text files can be found at the following locations:

* English (Security Patch 4):
http://www.trendmicro.com/download/product.asp?productid=17
* Japanese (Security Patch 2):
http://www.trendmicro.co.jp/download/product.asp?productid=17
* Traditional Chinese (Security Patch 3):
http://www.trendmicro.com/download/zh-tw/product.asp?productid=17

For additional questions and/or concerns, contact your local Trend Micro support representative.
Source : http://trendmicro.com

No comments: