Trend Micro HouseCall ActiveX Control Remote Code Execution Vulnerability
BID:32950
Info
Trend Micro HouseCall ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 32950 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2435 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 2008 12:00AM |
| Updated: | Dec 25 2008 03:51PM |
| Credit: | Alin Rad Pop |
| Vulnerable: |
Trend Micro HouseCall 6.6.0.1278 Trend Micro HouseCall 6.51.0.1028 |
| Not Vulnerable: |
Trend Micro HouseCall 6.6 1285 |
Discussion
Trend Micro HouseCall ActiveX Control Remote Code Execution Vulnerability
The Trend Micro HouseCall ActiveX control is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects HouseCall versions 6.51.0.1028 and 6.6.0.1278; other versions may be affected as well.
The Trend Micro HouseCall ActiveX control is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects HouseCall versions 6.51.0.1028 and 6.6.0.1278; other versions may be affected as well.
Exploit / POC
Trend Micro HouseCall ActiveX Control Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Trend Micro HouseCall ActiveX Control Remote Code Execution Vulnerability
Solution:
The vendor released HouseCall 6.6.0.1285 to address this issue. Please see the references for more information.
Solution:
The vendor released HouseCall 6.6.0.1285 to address this issue. Please see the references for more information.
References
Trend Micro HouseCall ActiveX Control Remote Code Execution Vulnerability
References:
References:
- HouseCall (Trend Micro)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Secunia Research: Trend Micro HouseCall notifyOnLoadNative() Vulnerability (Secunia)
- Secunia Research: Trend Micro HouseCall 'notifyOnLoadNative()' Vulnerability (Secunia Research
) - [Hot Fix] B1285 - Trend Micro HouseCall 6.6 ActiveX (Trend Micro)
- Vulnerability Note VU#702628 - Trend Micro HouseCall ActiveX control notifyOnLoa (US-CERT)