Trend Micro: The Only Anti-virus (and Vulnerability-Stricken!) Biggie on MS’ Certified for Vista List

執筆者
Lisa Vaas
Lisa Vaas
Published: Feb 23, 2007
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Why is it the only one there? It sure isn’t because of its track record of popping up in US-CERT for vulnerability warnings, at least as of today!

My former colleague and security blogger hero, Ryan Naraine, pointed out today that Microsoft’s just-released list of Vista-compatible apps lacks the anti-virus heavyweights: CA, Symantec, eTrust, McAfee. The only recognizable AV name on the list is Trend Micro.

How ironic is this: four buffer overflow vulnerabilities listed on US-CERT’s recent vulnerability notes list, all in Trend Micro’s ServerProtect product? ServerProtect provides anti-virus scanning for servers, detecting and removing viruses from files and compressed files in real time.

The flaws are all stack-based buffer overflow vulnerabilities. Here are where they’re located, how they’re triggered, and where the advisories and patches are:

1. A flaw in the ENG_SetRealTimeScanConfigInfo()routine can allow an overflow if triggered by sending a specially crafted RPC packet to an affected ServerProtect installation. Here’s the advisory. This could let in a remote, unauthenticated user, who could send out arbitrary commands. Trend Micro has a patch here. 2. The CMON_ActiveUpdate() and CMON_ActiveRollback() routines have flaws that can set off overflows if triggered by a specially crafted RPC packet sent to an affected installation. Here’s the advisory. Here’s the patch.

3. The CMON_NetTestConnection() routine has a flaw that can be used to set off an overflow if a specially crafted RPC packet is sent to an affected installation. The advisory is here, and here’s the patch. 4. The ENG_SendEMail() routine has a flaw that can set off an overflow by if a specially crafted RPC packet is sent to an affected Trend Micro ServerProtect installation. The advisory is here, and the patch is here.

Of course, it’s just a coincidence that Trend Micro’s got four stack-based buffer overflows showing up on the same day it made the Vista-compatible list. As for the rest of the AV biggies, I only managed to get CA on the phone, since I was curious about it, and the company’s explanation, at least, is perfectly reasonable.

Sam Curry, vice president of security management, pointed out that there are several degrees of certification from Microsoft. The first one is “Works with Windows Vista,” which CA has. CA has it by virtue of being a strategic Microsoft partner and having participated in the Vista beta program.

The second level of certification is “Certified with Windows Vista.” This one requires that all components be Microsoft components, or Vista-specific components. In CA’s case, you use a third-party installation software to plug CA’s applications in, which makes them ineligible for the “Certified With” label, but we can safely assume it doesn’t mean “Won’t work worth &^%$ with Vista.”

Lisa Vaas

Lisa Vaas

Content Writer

Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。