PT-2003-1774 · Trend Micro+1 · Trend Micro Damage Cleanup Server+2

Published

2003-08-05

·

Updated

2008-09-10

·

CVE-2003-0646

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Trend Micro HouseCall versions 5.5 through 5.7 Trend Micro Damage Cleanup Server version 1.0
Description: The issue is related to multiple buffer overflows in ActiveX controls. Remote attackers can execute arbitrary code by providing long parameter strings.
Recommendations: For Trend Micro HouseCall versions 5.5 through 5.7, consider disabling the affected ActiveX controls until a patch is available. For Trend Micro Damage Cleanup Server version 1.0, restrict access to the vulnerable ActiveX controls to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0646

Affected Products

Activex
Trend Micro Damage Cleanup Server
Trend Micro Housecall