Trend Micro ServerProtect Vulnerabilities

Users of Trend Micro ServerProtect are advised to update their file server protection software due to several vulnerabilities.

iDefense has issued an advisory regarding a vulnerability in ServerProtect Web user interface. When exploited, an attacker can gain full access to the product. The Linux version of ServerProtect is affected. Download the update from the Trend Micro Update Center here.

SecuriTeam has reported two stack overflow vulnerabilities (eng50.dll and StCommon.dll) for ServerProtect, which affects the Windows version (5.58), EMC (5.58), and Network Appliance Filer (5.61 and 5.62). The said vulnerabilities allow remote code execution using the SYSTEM user privilege.

Trend Micro has issued a response here.

ServerProtect users are advised to update their software. No known exploits in the wild yet.