PT-2007-6472 · G Data · G Data Antivirus

Published

2007-10-13

·

Updated

2018-10-15

·

CVE-2007-5436

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: G DATA Antivirus 2007
Description: A buffer overflow issue exists in a certain ActiveX control in ScanObjectBrowser.DLL, potentially allowing remote attackers to execute arbitrary code via unspecified parameters to the SelectPath function. This issue may not cross privilege boundaries in most environments, as it is not marked as safe for scripting.
Recommendations: For G DATA Antivirus 2007, consider disabling the SelectPath function as a temporary workaround until a patch is available. Restrict access to the vulnerable ActiveX control in ScanObjectBrowser.DLL to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5436

Affected Products

G Data Antivirus