Trend Micro Internet Security Pro ActiveX Control Remote Code Execution Vulnerability
BID:42717
Info
Trend Micro Internet Security Pro ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 42717 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2010 12:00AM |
| Updated: | Nov 18 2010 06:36AM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: |
Trend Micro Internet Security Pro 2010 |
| Not Vulnerable: | |
Discussion
Trend Micro Internet Security Pro ActiveX Control Remote Code Execution Vulnerability
Trend Micro Internet Security Pro is prone to a remote code-execution vulnerability that affects the 'AccWizObjects' ActiveX control.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application (typically Internet Explorer) that uses the ActiveX control.
Trend Micro Internet Security Pro 2010 is vulnerable; other versions may also be affected.
Trend Micro Internet Security Pro is prone to a remote code-execution vulnerability that affects the 'AccWizObjects' ActiveX control.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application (typically Internet Explorer) that uses the ActiveX control.
Trend Micro Internet Security Pro 2010 is vulnerable; other versions may also be affected.
Exploit / POC
Trend Micro Internet Security Pro ActiveX Control Remote Code Execution Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Trend Micro Internet Security Pro ActiveX Control Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Trend Micro Internet Security Pro ActiveX Control Remote Code Execution Vulnerability
References:
References:
- [Hot Fix] UfPBCtrl.dll is vulnerable to remote attackers (Trend Micro)
- Trend Micro Homepage (Trend Micro)
- Trend Micro Internet Security Pro 2010 ActiveX extSetOwner Remote Code Execution (Trend Micro)