PT-2007-6472 · G Data · G Data Antivirus

Publicado

2007-10-13

·

Atualizado

2018-10-15

·

CVE-2007-5436

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: G DATA Antivirus 2007
Description: A buffer overflow issue exists in a certain ActiveX control in ScanObjectBrowser.DLL, potentially allowing remote attackers to execute arbitrary code via unspecified parameters to the SelectPath function. This issue may not cross privilege boundaries in most environments, as it is not marked as safe for scripting.
Recommendations: For G DATA Antivirus 2007, consider disabling the SelectPath function as a temporary workaround until a patch is available. Restrict access to the vulnerable ActiveX control in ScanObjectBrowser.DLL to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5436

Produtos afetados

G Data Antivirus