PT-2007-1797 · Trend Micro · Trend Micro Officescan+3
CVE-2007-0325
·
Published
2007-02-20
·
Updated
2011-03-08
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Trend Micro OfficeScan versions 7.0 through 7.0 before Build 1344
Trend Micro OfficeScan versions 7.3 through 7.3 before Build 1241
Trend Micro Client / Server / Messaging Security versions 3.0 through 3.0 before Build 1197
Description:
The issue is related to multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control. This allows remote attackers to execute arbitrary code via a crafted HTML document.
Recommendations:
For Trend Micro OfficeScan version 7.0, update to Build 1344 or later.
For Trend Micro OfficeScan version 7.3, update to Build 1241 or later.
For Trend Micro Client / Server / Messaging Security version 3.0, update to Build 1197 or later.
Exploit
Fix
DoS
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Client / Server / Messaging Security
Trend Micro Officescan
Trend Micro Officescan Client
Trend Micro Officescan Server