PT-2010-4629 · Trend Micro · Trend Micro Internet Security Pro

Published

2010-08-31

·

Updated

2018-10-10

·

CVE-2010-3189

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro Internet Security Pro version 2010
Description The issue concerns the extSetOwner function in the UfProxyBrowserCtrl ActiveX control, which allows remote attackers to execute arbitrary code via an invalid address that is dereferenced as a pointer. This is related to the UfPBCtrl.dll component.
Recommendations For Trend Micro Internet Security Pro version 2010, consider disabling the extSetOwner function in the UfProxyBrowserCtrl ActiveX control as a temporary workaround until a patch is available. Restrict access to the UfPBCtrl.dll component to minimize the risk of exploitation.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3189

Affected Products

Trend Micro Internet Security Pro