PT-2008-4767 · Trend Micro · Worry-Free Business Security+4
E.B
·
Published
2008-07-30
·
Updated
2017-09-29
·
CVE-2008-3364
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment versions 7.0 through 7.3 build 1343 Patch 4
Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment version 8.0
Client Server Messaging Security (CSM) versions 3.5 through 3.6
Worry-Free Business Security (WFBS) version 5.0
Description
The issue is caused by boundary errors in the OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class ActiveX control, allowing remote attackers to execute arbitrary code via a long string in the
Server property, and possibly other properties. This can be exploited when a user visits a malicious web site, resulting in a stack-based buffer overflow. Successful exploitation requires that the OfficeScan client was installed using web deployment.Recommendations
For Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment versions 7.0 through 7.3 build 1343 Patch 4, consider disabling the
ObjRemoveCtrl Class ActiveX control until a patch is available.
For Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment version 8.0, restrict access to the OfficeScanRemoveCtrl.dll to minimize the risk of exploitation.
For Client Server Messaging Security (CSM) versions 3.5 through 3.6, avoid using the Server property in the affected ActiveX control until the issue is resolved.
For Worry-Free Business Security (WFBS) version 5.0, as a temporary workaround, consider disabling the ObjRemoveCtrl Class ActiveX control until a patch is available.Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Client Server Messaging Security
Trend Micro Officescan Corporate Edition
Trend Micro Officescan Client
Trend Micro Officescan Server
Worry-Free Business Security