Trend Micro Multiple Products Network Security Component Modules Multiple Vulnerabilities
BID:33358
Info
Trend Micro Multiple Products Network Security Component Modules Multiple Vulnerabilities
| Bugtraq ID: | 33358 |
| Class: | Unknown |
| CVE: |
CVE-2008-3864 CVE-2008-3865 CVE-2008-3866 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2009 12:00AM |
| Updated: | Feb 06 2009 04:18PM |
| Credit: | Carsten Eiram, Secunia Research |
| Vulnerable: |
Trend Micro PC-Cillin Internet Security 2007 Trend Micro OfficeScan Corporate Edition 8.0 SP1 Patch 1 Trend Micro Internet Security Pro 2008 Trend Micro Internet Security 2008 |
| Not Vulnerable: | |
Discussion
Trend Micro Multiple Products Network Security Component Modules Multiple Vulnerabilities
Multiple products from Trend Micro are prone to multiple security vulnerabilities that affect the Network Security Component modules.
Successful exploits may allow an attacker to crash an affected application, execute arbitrary code, or bypass security.
These issues affect the following:
Trend Micro OfficeScan Corporate Edition 8.0 SP1 Patch 1
Trend Micro Internet Security 2008
Trend Micro Internet Security Pro 2008
Trend Micro PC-cillin Internet Security 2007
Multiple products from Trend Micro are prone to multiple security vulnerabilities that affect the Network Security Component modules.
Successful exploits may allow an attacker to crash an affected application, execute arbitrary code, or bypass security.
These issues affect the following:
Trend Micro OfficeScan Corporate Edition 8.0 SP1 Patch 1
Trend Micro Internet Security 2008
Trend Micro Internet Security Pro 2008
Trend Micro PC-cillin Internet Security 2007
Exploit / POC
Trend Micro Multiple Products Network Security Component Modules Multiple Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service for CVE-2008-3865. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service for CVE-2008-3865. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Trend Micro Multiple Products Network Security Component Modules Multiple Vulnerabilities
Solution:
The vendor released a patch to address these issues in OfficeScan Corporate Edition. Reports indicate that patches for the other products should also become available shortly. Please see the references for more information.
Trend Micro OfficeScan Corporate Edition 8.0 SP1 Patch 1
Solution:
The vendor released a patch to address these issues in OfficeScan Corporate Edition. Reports indicate that patches for the other products should also become available shortly. Please see the references for more information.
Trend Micro OfficeScan Corporate Edition 8.0 SP1 Patch 1
-
Trend Micro OSCE_8.0_SP1_Patch1_Win_EN_CriticalPatch_B3191.exe
http://www.trendmicro.com/ftp/products/patches/OSCE_8.0_SP1_Patch1_Win _EN_CriticalPatch_B3191.exe
References
Trend Micro Multiple Products Network Security Component Modules Multiple Vulnerabilities
References:
References:
- Trend Micro Network Security Component Vulnerabilities (Secunia)
- Trend Micro NSC Firewall Configuration Vulnerability (Secunia)
- Trend Micro OfficeScan Homepage (Trend Micro)
- Secunia Research: Trend Micro Network Security Component Vulnerabilities (Secunia Research
) - Trend Micro(TM) OfficeScan(TM) Critical Patch - Server Build 3191 and NSC module (Trend Micro)