Trend Micro HouseCall ActiveX Control Library File Remote Code Execution Vulnerability
BID:32965
Info
Trend Micro HouseCall ActiveX Control Library File Remote Code Execution Vulnerability
| Bugtraq ID: | 32965 |
| Class: | Design Error |
| CVE: |
CVE-2008-2434 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2008 12:00AM |
| Updated: | Dec 29 2008 04:21PM |
| Credit: | Alin Rad Pop |
| Vulnerable: |
Trend Micro HouseCall 6.6.0.1278 Trend Micro HouseCall 6.51.0.1028 |
| Not Vulnerable: |
Trend Micro HouseCall 6.6 1285 |
Discussion
Trend Micro HouseCall ActiveX Control Library File Remote Code Execution Vulnerability
The Trend Micro HouseCall ActiveX control is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects HouseCall 6.51.0.1028 and 6.6.0.1278; other versions may be affected as well.
The Trend Micro HouseCall ActiveX control is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects HouseCall 6.51.0.1028 and 6.6.0.1278; other versions may be affected as well.
Exploit / POC
Trend Micro HouseCall ActiveX Control Library File Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Trend Micro HouseCall ActiveX Control Library File Remote Code Execution Vulnerability
Solution:
The vendor released HouseCall 6.6.0.1285 to address this issue. Please see the references for more information.
Solution:
The vendor released HouseCall 6.6.0.1285 to address this issue. Please see the references for more information.
References
Trend Micro HouseCall ActiveX Control Library File Remote Code Execution Vulnerability
References:
References:
- HouseCall (Trend Micro)
- Secunia Research: Trend Micro HouseCall ActiveX Control Arbitrary Code Execution (Secunia Research
) - [Hot Fix] B1285 - Trend Micro HouseCall 6.6 ActiveX (Trend Micro)
- Trend Micro HouseCall ActiveX Control Arbitrary Code Execution (Secunia Research)
- Vulnerability Note VU#541025 (US-CERT)