<<<>>> Trend Micro, Inc. December 16, 2010 ====================================================================== Trend Micro(TM) Control Manager(TM) 5.0 Critical Patch - Build 2017 ====================================================================== Contents =================================================================== 1. Overview of this Critical Patch Release 1.1 Files Included in this Release 2. Documentation Set 3. System Requirements 4. Installation/ Uninstallation 4.1 Installation 4.2 Uninstallation 5. Post-installation Configuration 6. Known Issues 7. Release History 8. Contact Information 9. About Trend Micro 10. License Agreement =================================================================== 1. Overview of this Critical Patch Release ======================================================================== NOTE: Please install the critical patch before completing any procedures in this section (see "Installation"). This critical patch resolves the following issue(s): Issue: There is a vulnerability in the "mrf.exe" TMI service module that allows the attacker to execute an arbitrary code on vulnerable installations of Trent Micro Control Manager. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: This Critical Patch addresses the vulnerability issue and prevents malicious attacks. 1.1 Files Included in This Release ===================================================================== A. Files for Current Issue(s) --------------------------------------------------------------------- A. Files for Current Issue --------------------------------------------------------------------- Module File Name Build No. ================ ========= \FileGroup1\ libMRF_AP.dll 1.12.0.1156 libMRF_CM.dll 1.12.0.1156 libMRF_Common.dll 1.12.0.1156 libMRF_DM.dll 1.12.0.1156 libMRF_Entity.dll 1.12.0.1156 libTMI_DataMarshal.dll 1.12.0.1156 mrf.exe 1.12.0.1156 MRF_CM.dll 1.12.0.1156 B. Files for Previous Issues --------------------------------------------------------------------- 2. Documentation Set ======================================================================== In addition to this readme.txt, the documentation set for this product includes the following: o Installation Guide (IG) -- Provides product overview, deployment plan, installation steps and basic information intended to help you deploy IMSS smoothly. o Administrator's Guide (AG) -- Provides post-installation instructions on how to configure the settings to help you get IMSS "up and running". Also includes instructions on performing other administrative tasks for the day-to-day maintenance of IMSS. o Readme.txt files -- version enhancements, basic installation, known issues, and release history. There is one readme for IMSS and one for Spam Prevention Solution, which includes IP Profiler. o Electronic versions of the printed manuals are available at: www.trendmicro.com/download/ o Online help -- Context-sensitive help screens that provide guidance for performing a task. o TrendEdge is a program for Trend Micro employees, partners, and other interested parties that provides information on unsupported, innovative techniques, tools, and best practices for Trend Micro products. The TrendEdge database contains numerous documents covering a wide range of topics. http://trendedge.trendmicro.com o Knowledge Base -- a searchable database of known product issues, including specific problem-solving and troubleshooting topics. http://esupport.trendmicro.com 3. System Requirements ======================================================================== Install Control Manager 5.0 before installing this hot fix. 4. Installation/Uninstallation ======================================================================== 4.1 Installation ===================================================================== To install Critical Patch 2017: 1. Install Control Manager 5.0. If this has been previously installed, proceed with the next step. 2. Copy the "tmcm_50_win_en_criticalpatch2017.exe" file to the Control Manager server folder. 3. Run "tmcm_50_win_en_criticalpatch2017.exe" on the Control Manager. A confirmation dialog box displays "Installation successful!" after the system completes the installation. 4.2 Uninstallation ===================================================================== To roll back to the previous Control Manager 5.0 build: 1. Obtain the Critical Patch 2017 backup path information from the registry key: \HKEY_Local_Machine\Software\TrendMicro\TVCS\CriticalPatch\B2017 \Backup Dir 2. Open the backup folder. For example: C:\Program files\Trend Micro\Control Manager\Hotfix \Bxxxx-B2017 3. Double-click "Uninstall.bat". A confirmation dialog box displays "Uninstallation successful!" after the system completes the rollback process. Control Manager 5.0 service packs, patches, and hot fixes can be found on the Trend Micro Web site or obtained from a technical support engineer. http://www.trendmicro.com/download/product.asp?productid=7 5. Post-Installation Configuration ======================================================================== No post-installation steps are required. Note: Trend Micro recommends that you update your scan engine and virus pattern files immediately after installing the product. 6. Known Issues ======================================================================== There are no known issues for this critical patch release. 7. Release History ======================================================================== See the following website for a more information about updates to this product: http://www.trendmicro.com/download 8. Contact Information ======================================================================== A license to the Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, Maintenance must be renewed on an annual basis at Trend Micro's then-current Maintenance fees. You can contact Trend Micro via fax, phone, and email, or visit us at: http://www.trendmicro.com Evaluation copies of Trend Micro products can be downloaded from our Web site. Global Mailing Address/Telephone numbers ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ For global contact information in the Asia/Pacific region, Australia and New Zealand, Europe, Latin America, and Canada, refer to: http://www.trendmicro.com/en/about/overview.htm The Trend Micro "About Us" screen displays. Click the appropriate link in the "Contact Us" section of the screen. Note: This information is subject to change without notice. 9. About Trend Micro ======================================================================== Trend Micro, Inc. provides virus protection, anti-spam, and content-filtering security products and services. Trend Micro allows companies worldwide to stop viruses and other malicious code from a central point before they can reach the desktop. Copyright 2010, Trend Micro Incorporated. All rights reserved. Trend Micro, the t-ball logo, OfficeScan, InterScan, and Control Manager are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other marks are the trademarks or registered trademarks of their respective companies. 10. License Agreement ======================================================================== Information about your license agreement with Trend Micro can be viewed at: http://www.trendmicro.com/en/purchase/license/ Third-party licensing agreements can be viewed: - By selecting the "About" option in the application user interface - By referring to the "Legal" page of the Getting Started Guide or Administrator's Guide