Trend Micro InterScan Messaging Security Suite (IMSS) ISNTSmtp insecure directory permissions
| imss-isntsmtp-directory-permissions (25415) |
Description:
Trend Micro InterScan Messaging Security Suite (IMSS) could allow a local attacker to gain elevated privileges. The ISNTSmtp directory is created with insecure permissions. A local attacker could exploit this vulnerability by replacing .exe files within the directory with Trojans, which could allow the attacker to execute arbitrary code with elevated privileges when the system is restarted or when another user logs on.
Platforms Affected:
- Trend Micro, InterScan Messaging Security Suite 5.5 build 1183
Remedy:
Upgrade to the latest versions of InterScan Messaging Security Suite (5.7.0.11121 or later), available from the InterScan Messaging Security Suite Web site. See References.
Consequences:
Gain Privileges
References:
- InterScan Messaging Security Suite Web site, InterScan Messaging Security Suite at http://www.trendmicro.com/en/products/gateway/ismss/evaluate/overview.htm.
- CVE-2006-1380: ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.
- CVE-2006-1381: Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.
- SA11576: Trend Micro OfficeScan Insecure Registry Key and Directory Permissions
- SA19022: InterScan Messaging Security Suite Insecure Default Directory Permissions
- VUPEN/ADV-2006-1041: Trend Micro InterScan Messaging ISNTSmtp Directory Insecure Permissions
Reported:
Mar 22, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
