CVE-2007-0851

Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable.

Published: 2007-02-08 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2007-0851 is rated High Risk (70.5/100): CVSS Critical severity, with high exploitation likelihood (EPSS 35.25%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2007-0851

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-11-19 35.82% 35.25% -0.57%
2 2025-09-27 34.98% 35.82% +0.84%
3 2025-04-25 34.98%

Full EPSS history (15 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2007-0851

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.3 2.0 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
8.6 10.0 [email protected]

Weakness enumeration for CVE-2007-0851

NVD evaluator notes for CVE-2007-0851

Impact: Failed exploit attempts will likely cause a denial-of-service condition.

Affected software / configurations for CVE-2007-0851

Vendor Product Version Raw CPE
trend_micro client-server-messaging_suite_smb gold cpe:2.3:a:trend_micro:client-server-messaging_suite_smb:gold:*:windows:*:*:*:*:*
trend_micro client-server_suite_smb gold cpe:2.3:a:trend_micro:client-server_suite_smb:gold:*:windows:*:*:*:*:*
trend_micro control_manager 2.5.0 cpe:2.3:a:trend_micro:control_manager:2.5.0:*:*:*:*:*:*:*
trend_micro control_manager 3.5 cpe:2.3:a:trend_micro:control_manager:3.5:*:*:*:*:*:*:*
trend_micro control_manager gold cpe:2.3:a:trend_micro:control_manager:gold:*:as_400:*:*:*:*:*
trend_micro control_manager gold cpe:2.3:a:trend_micro:control_manager:gold:*:s_390:*:*:*:*:*
trend_micro control_manager gold cpe:2.3:a:trend_micro:control_manager:gold:*:solaris:*:*:*:*:*
trend_micro control_manager gold cpe:2.3:a:trend_micro:control_manager:gold:*:windows:*:*:*:*:*
trend_micro control_manager gold cpe:2.3:a:trend_micro:control_manager:gold:*:windows_nt:*:*:*:*:*
trend_micro control_manager netware cpe:2.3:a:trend_micro:control_manager:netware:*:*:*:*:*:*:*
trend_micro interscan_emanager 3.5 cpe:2.3:a:trend_micro:interscan_emanager:3.5:*:hp:*:*:*:*:*
trend_micro interscan_emanager 3.5.2 cpe:2.3:a:trend_micro:interscan_emanager:3.5.2:*:windows:*:*:*:*:*
trend_micro interscan_emanager 3.6 cpe:2.3:a:trend_micro:interscan_emanager:3.6:*:linux:*:*:*:*:*
trend_micro interscan_emanager 3.6 cpe:2.3:a:trend_micro:interscan_emanager:3.6:*:sun:*:*:*:*:*
trend_micro interscan_emanager 3.51 cpe:2.3:a:trend_micro:interscan_emanager:3.51:*:*:*:*:*:*:*
trend_micro interscan_emanager 3.51_j cpe:2.3:a:trend_micro:interscan_emanager:3.51_j:*:*:*:*:*:*:*
trend_micro interscan_messaging_security_suite cpe:2.3:a:trend_micro:interscan_messaging_security_suite:*:*:linux_5.1.1:*:*:*:*:*
trend_micro interscan_messaging_security_suite 3.81 cpe:2.3:a:trend_micro:interscan_messaging_security_suite:3.81:*:*:*:*:*:*:*
trend_micro interscan_messaging_security_suite 5.5 cpe:2.3:a:trend_micro:interscan_messaging_security_suite:5.5:*:*:*:*:*:*:*
trend_micro interscan_messaging_security_suite 5.5_build_1183 cpe:2.3:a:trend_micro:interscan_messaging_security_suite:5.5_build_1183:*:*:*:*:*:*:*
trend_micro interscan_messaging_security_suite gold cpe:2.3:a:trend_micro:interscan_messaging_security_suite:gold:*:linux:*:*:*:*:*
trend_micro interscan_messaging_security_suite gold cpe:2.3:a:trend_micro:interscan_messaging_security_suite:gold:*:solaris:*:*:*:*:*
trend_micro interscan_messaging_security_suite gold cpe:2.3:a:trend_micro:interscan_messaging_security_suite:gold:*:windows:*:*:*:*:*
trend_micro interscan_viruswall 3.0.1 cpe:2.3:a:trend_micro:interscan_viruswall:3.0.1:*:linux:*:*:*:*:*
trend_micro interscan_viruswall 3.0.1 cpe:2.3:a:trend_micro:interscan_viruswall:3.0.1:*:unix:*:*:*:*:*
trend_micro interscan_viruswall 3.1.0 cpe:2.3:a:trend_micro:interscan_viruswall:3.1.0:*:linux:*:*:*:*:*
trend_micro interscan_viruswall 3.2.3 cpe:2.3:a:trend_micro:interscan_viruswall:3.2.3:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.3 cpe:2.3:a:trend_micro:interscan_viruswall:3.3:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.6 cpe:2.3:a:trend_micro:interscan_viruswall:3.6:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.6 cpe:2.3:a:trend_micro:interscan_viruswall:3.6:*:hp_ux:*:*:*:*:*
trend_micro interscan_viruswall 3.6 cpe:2.3:a:trend_micro:interscan_viruswall:3.6:*:solaris:*:*:*:*:*
trend_micro interscan_viruswall 3.6 cpe:2.3:a:trend_micro:interscan_viruswall:3.6:*:windows_nt:*:*:*:*:*
trend_micro interscan_viruswall 3.6.0_build_1182 cpe:2.3:a:trend_micro:interscan_viruswall:3.6.0_build_1182:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.6.0_build1166 cpe:2.3:a:trend_micro:interscan_viruswall:3.6.0_build1166:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.6.5 cpe:2.3:a:trend_micro:interscan_viruswall:3.6.5:*:linux:*:*:*:*:*
trend_micro interscan_viruswall 3.7.0 cpe:2.3:a:trend_micro:interscan_viruswall:3.7.0:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.7.0_build1190 cpe:2.3:a:trend_micro:interscan_viruswall:3.7.0_build1190:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.8.0_build1130 cpe:2.3:a:trend_micro:interscan_viruswall:3.8.0_build1130:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.32 cpe:2.3:a:trend_micro:interscan_viruswall:3.32:*:*:*:*:*:*:*
trend_micro interscan_viruswall 3.81 cpe:2.3:a:trend_micro:interscan_viruswall:3.81:*:linux:*:*:*:*:*
trend_micro interscan_viruswall 5.1 cpe:2.3:a:trend_micro:interscan_viruswall:5.1:*:windows_nt:*:*:*:*:*
trend_micro interscan_viruswall gold cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:aix:*:*:*:*:*
trend_micro interscan_viruswall gold cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:linux_for_smb:*:*:*:*:*
trend_micro interscan_viruswall gold cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:smb:*:*:*:*:*
trend_micro interscan_viruswall gold cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:windows:*:*:*:*:*
trend_micro interscan_viruswall gold cpe:2.3:a:trend_micro:interscan_viruswall:gold:*:windows_nt_for_smb:*:*:*:*:*
trend_micro interscan_viruswall_for_windows_nt 3.4 cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.4:*:*:*:*:*:*:*
trend_micro interscan_viruswall_for_windows_nt 3.5 cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.5:*:*:*:*:*:*:*
trend_micro interscan_viruswall_for_windows_nt 3.6 cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.6:*:*:*:*:*:*:*
trend_micro interscan_viruswall_for_windows_nt 3.51 cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.51:*:*:*:*:*:*:*
trend_micro interscan_viruswall_for_windows_nt 3.52 cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.52:*:*:*:*:*:*:*
trend_micro interscan_viruswall_for_windows_nt 3.52_build1466 cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:3.52_build1466:*:*:*:*:*:*:*
trend_micro interscan_viruswall_for_windows_nt 5.1.0 cpe:2.3:a:trend_micro:interscan_viruswall_for_windows_nt:5.1.0:*:*:*:*:*:*:*
trend_micro interscan_viruswall_scan_engine 7.510.0-1002 cpe:2.3:a:trend_micro:interscan_viruswall_scan_engine:7.510.0-1002:*:*:*:*:*:*:*
trend_micro interscan_web_security_suite cpe:2.3:a:trend_micro:interscan_web_security_suite:*:*:linux:*:*:*:*:*
trend_micro interscan_web_security_suite cpe:2.3:a:trend_micro:interscan_web_security_suite:*:*:linux_1.0.0_ja:*:*:*:*:*
trend_micro interscan_web_security_suite gold cpe:2.3:a:trend_micro:interscan_web_security_suite:gold:*:linux:*:*:*:*:*
trend_micro interscan_web_security_suite gold cpe:2.3:a:trend_micro:interscan_web_security_suite:gold:*:solaris:*:*:*:*:*
trend_micro interscan_web_security_suite gold cpe:2.3:a:trend_micro:interscan_web_security_suite:gold:*:windows:*:*:*:*:*
trend_micro interscan_webmanager 1.2 cpe:2.3:a:trend_micro:interscan_webmanager:1.2:*:*:*:*:*:*:*
trend_micro interscan_webmanager 2.0 cpe:2.3:a:trend_micro:interscan_webmanager:2.0:*:*:*:*:*:*:*
trend_micro interscan_webmanager 2.1 cpe:2.3:a:trend_micro:interscan_webmanager:2.1:*:*:*:*:*:*:*
trend_micro interscan_webprotect gold cpe:2.3:a:trend_micro:interscan_webprotect:gold:*:isa:*:*:*:*:*
trend_micro officescan 3.0 cpe:2.3:a:trend_micro:officescan:3.0:*:corporate:*:*:*:*:*
trend_micro officescan 4.5.0 cpe:2.3:a:trend_micro:officescan:4.5.0:*:microsof_sbs:*:*:*:*:*
trend_micro officescan 7.3 cpe:2.3:a:trend_micro:officescan:7.3:*:*:*:*:*:*:*
trend_micro officescan corporate_3.0 cpe:2.3:a:trend_micro:officescan:corporate_3.0:*:windows_nt_server:*:*:*:*:*
trend_micro officescan corporate_3.1.1 cpe:2.3:a:trend_micro:officescan:corporate_3.1.1:*:windows_nt_server:*:*:*:*:*
trend_micro officescan corporate_3.5 cpe:2.3:a:trend_micro:officescan:corporate_3.5:*:*:*:*:*:*:*
trend_micro officescan corporate_3.5 cpe:2.3:a:trend_micro:officescan:corporate_3.5:*:windows_nt_server:*:*:*:*:*
trend_micro officescan corporate_3.11 cpe:2.3:a:trend_micro:officescan:corporate_3.11:*:*:*:*:*:*:*
trend_micro officescan corporate_3.11 cpe:2.3:a:trend_micro:officescan:corporate_3.11:*:windows_nt_server:*:*:*:*:*
trend_micro officescan corporate_3.13 cpe:2.3:a:trend_micro:officescan:corporate_3.13:*:*:*:*:*:*:*
trend_micro officescan corporate_3.13 cpe:2.3:a:trend_micro:officescan:corporate_3.13:*:windows_nt_server:*:*:*:*:*
trend_micro officescan corporate_3.54 cpe:2.3:a:trend_micro:officescan:corporate_3.54:*:*:*:*:*:*:*
trend_micro officescan corporate_5.02 cpe:2.3:a:trend_micro:officescan:corporate_5.02:*:*:*:*:*:*:*
trend_micro officescan corporate_5.5 cpe:2.3:a:trend_micro:officescan:corporate_5.5:*:*:*:*:*:*:*
trend_micro officescan corporate_5.58 cpe:2.3:a:trend_micro:officescan:corporate_5.58:*:*:*:*:*:*:*
trend_micro officescan corporate_6.5 cpe:2.3:a:trend_micro:officescan:corporate_6.5:*:*:*:*:*:*:*
trend_micro officescan corporate_7.0 cpe:2.3:a:trend_micro:officescan:corporate_7.0:*:*:*:*:*:*:*

References for CVE-2007-0851

URL Tags
http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034289 Patch Vendor Advisory
http://jvn.jp/jp/JVN%2377366274/index.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=470 Patch Vendor Advisory
http://osvdb.org/33038
http://secunia.com/advisories/24087 Patch Vendor Advisory
http://secunia.com/advisories/24128
http://securitytracker.com/id?1017601 Patch Vendor Advisory
http://securitytracker.com/id?1017602
http://securitytracker.com/id?1017603
http://www.jpcert.or.jp/at/2007/at070004.txt
http://www.kb.cert.org/vuls/id/276432 US Government Resource
http://www.securityfocus.com/bid/22449 Patch Vendor Advisory
http://www.vupen.com/english/advisories/2007/0522
http://www.vupen.com/english/advisories/2007/0569
https://exchange.xforce.ibmcloud.com/vulnerabilities/32352
cvelogic Threat Intelligence