CVE Feed

    Dashboard / CVE / CVE-2007-0856

    CVE-2007-0856

    TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.

    Published:Feb 8, 2007
    Last Modified:Apr 23, 2026
    EPS:Feb 8, 2007
    EPSS Score:0.0015
    CVSS Score:7.2

    Affected Products

    Vendor
    Trend Micro
    Product
    Client-server-messaging Security
    Vendor
    Trend Micro
    Product
    Damage Cleanup Services
    Vendor
    Trend Micro
    Product
    Pc-cillin Internet Security
    Vendor
    Trend Micro
    Product
    Tmcomm.sys
    Vendor
    Trend Micro
    Product
    Trend Micro Antirootkit Common Module
    Vendor
    Trend Micro
    Product
    Trend Micro Antispyware
    Vendor
    Trend Micro
    Product
    Trend Micro Antivirus
    Vendor
    Trend Micro
    Product
    Vsapini.sys

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High