Trend Micro OfficeScan POP3 Module Shared Section Insecure Permissions Vulnerability
BID:14448
Info
Trend Micro OfficeScan POP3 Module Shared Section Insecure Permissions Vulnerability
| Bugtraq ID: | 14448 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 01 2005 12:00AM |
| Updated: | Aug 01 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Trend Micro OfficeScan Corporate Edition 5.58 |
| Not Vulnerable: | |
Discussion
Trend Micro OfficeScan POP3 Module Shared Section Insecure Permissions Vulnerability
Trend Micro OfficeScan pop3 module utilizes Shared Sections in an insecure manner.
Attackers may read the data stored in the affected memory region, gaining access to potentially sensitive information. They may also write arbitrary data to the shared memory segment.
By writing data to this region, they may alter the message that is displayed to the user when the pop3 module intercepts malware in email. This may be utilized in social engineering attacks.
This vulnerability may possibly be exploited to crash the OfficeScan service, or potentially execute arbitrary machine code with System level privileges. This has not been confirmed.
This vulnerability is reported in version 5.58 of OfficeScan. Other versions may also be affected.
Trend Micro OfficeScan pop3 module utilizes Shared Sections in an insecure manner.
Attackers may read the data stored in the affected memory region, gaining access to potentially sensitive information. They may also write arbitrary data to the shared memory segment.
By writing data to this region, they may alter the message that is displayed to the user when the pop3 module intercepts malware in email. This may be utilized in social engineering attacks.
This vulnerability may possibly be exploited to crash the OfficeScan service, or potentially execute arbitrary machine code with System level privileges. This has not been confirmed.
This vulnerability is reported in version 5.58 of OfficeScan. Other versions may also be affected.
Exploit / POC
Trend Micro OfficeScan POP3 Module Shared Section Insecure Permissions Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Trend Micro OfficeScan POP3 Module Shared Section Insecure Permissions Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Trend Micro OfficeScan POP3 Module Shared Section Insecure Permissions Vulnerability
References:
References: