CVE-2008-3865 describes multiple heap-based buffer overflows in the ApiThread function of the firewall service (TmPfw.exe) within Trend Micro Network Security Component (NSC) modules. This vulnerability affects Trend Micro OfficeScan 8.0 SP1 Patch 1, Internet Security 2007, and Internet Security 2008 17.0.1224. The vulnerability carries a critical CVSS score of 10.0, indicating it is easily exploitable remotely without authentication (AV:N/AC:L/Au:N) and can lead to complete compromise of confidentiality, integrity, and availability (C:C/I:C/A:C). Attackers can trigger this by sending a specially crafted packet with a small value in an unspecified size field, potentially allowing arbitrary code execution. Despite its high severity and FAUCET Risk Score of 96/100, there is no evidence of active exploitation (not in KEV), nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:trend_micro:internet_security_2007:*:*:*:*:*:*:*:* | ||
17.0.1224CPE matchmatch criteria | cpe:2.3:a:trend_micro:internet_security_2008:17.0.1224:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:trend_micro:officescan:8.0:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.