PT-2007-1797 · Trend Micro · Trend Micro Officescan+3

Publicado

2007-02-20

·

Atualizado

2011-03-08

·

CVE-2007-0325

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Trend Micro OfficeScan versions 7.0 through 7.0 before Build 1344 Trend Micro OfficeScan versions 7.3 through 7.3 before Build 1241 Trend Micro Client / Server / Messaging Security versions 3.0 through 3.0 before Build 1197
Description: The issue is related to multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control. This allows remote attackers to execute arbitrary code via a crafted HTML document.
Recommendations: For Trend Micro OfficeScan version 7.0, update to Build 1344 or later. For Trend Micro OfficeScan version 7.3, update to Build 1241 or later. For Trend Micro Client / Server / Messaging Security version 3.0, update to Build 1197 or later.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-0325

Produtos afetados

Trend Micro Client / Server / Messaging Security
Trend Micro Officescan
Trend Micro Officescan Client
Trend Micro Officescan Server