Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format String Vulnerability
BID:20284
Info
Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format String Vulnerability
| Bugtraq ID: | 20284 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2006 12:00AM |
| Updated: | Oct 02 2006 07:15PM |
| Credit: | Discovered by Deral Heiland. |
| Vulnerable: |
Trend Micro OfficeScan Corporate Edition 7.3 |
| Not Vulnerable: | |
Discussion
Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format String Vulnerability
Trend Micro OfficeScan is prone to a remote format-string vulnerability. This vulnerability requires a certain amount of user-interaction for an attack to occur, such as visiting a malicious website. A successful exploit would let a remote attacker execute code with the privileges of the currently logged-in user.
Trend Micro OfficeScan Corporate Edition 7.3 is reported vulnerable. Other versions may be affected as well.
Trend Micro OfficeScan is prone to a remote format-string vulnerability. This vulnerability requires a certain amount of user-interaction for an attack to occur, such as visiting a malicious website. A successful exploit would let a remote attacker execute code with the privileges of the currently logged-in user.
Trend Micro OfficeScan Corporate Edition 7.3 is reported vulnerable. Other versions may be affected as well.
Exploit / POC
Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format String Vulnerability
Solution:
Reports indicate that the vendor has addressed this issue in OfficeScan Corporate Edition 7.3 Patch 1. Symantec was unable to confirm this information. Please contact the vendor for more information.
Solution:
Reports indicate that the vendor has addressed this issue in OfficeScan Corporate Edition 7.3 Patch 1. Symantec was unable to confirm this information. Please contact the vendor for more information.
References
Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format String Vulnerability
References:
References:
- Layered Defense Research Advisory 1 October 2006 (Layered Defense Research)
- Trend Micro OfficeScan Product Homepage (Trend Micro)