Get a Pentest and security assessment of your IT network.

Advisories

Trend Micro NSC Firewall Configuration Vulnerability

Secunia Research has discovered a vulnerability in Trend Micro Network Security Component (NSC) modules as bundled with various products. This can be exploited by malicious, local users to manipulate firewall settings regardless of configured security settings. Trend Micro Internet Security includes a management interface for users to configure e.g. the firewall settings. To prevent any user from changing the settings, password restriction can be enabled. However, the password check is implemented in the configuration GUI and not in the Trend Micro Personal Firewall service (TmPfw.exe). This can be exploited to manipulate the firewall settings regardless of whether password restriction is enabled by sending specially crafted packets to the service listening on port 40000/TCP.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74170/secunia-tmnscfirewall.txt

Source: https://packetstormsecurity.com/files/74170/Trend-Micro-NSC-Firewall-Configuration-Vulnerability.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.061