PT-2007-1797 · Trend Micro · Trend Micro Officescan+3

CVE-2007-0325

·

Published

2007-02-20

·

Updated

2011-03-08

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Trend Micro OfficeScan versions 7.0 through 7.0 before Build 1344 Trend Micro OfficeScan versions 7.3 through 7.3 before Build 1241 Trend Micro Client / Server / Messaging Security versions 3.0 through 3.0 before Build 1197
Description: The issue is related to multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control. This allows remote attackers to execute arbitrary code via a crafted HTML document.
Recommendations: For Trend Micro OfficeScan version 7.0, update to Build 1344 or later. For Trend Micro OfficeScan version 7.3, update to Build 1241 or later. For Trend Micro Client / Server / Messaging Security version 3.0, update to Build 1197 or later.

Exploit

Fix

DoS

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0325

Affected Products

Trend Micro Client / Server / Messaging Security
Trend Micro Officescan
Trend Micro Officescan Client
Trend Micro Officescan Server