Canary Labs Trend Link ActiveX Control 'SaveToFile()' Insecure Method Vulnerability
BID:58944
Info
Canary Labs Trend Link ActiveX Control 'SaveToFile()' Insecure Method Vulnerability
| Bugtraq ID: | 58944 |
| Class: | Design Error |
| CVE: |
CVE-2012-3022 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2013 12:00AM |
| Updated: | Apr 08 2013 12:00AM |
| Credit: | Kuang-Chun Hung |
| Vulnerable: |
Canary Labs Trend Link 9.0.2.27051 |
| Not Vulnerable: | |
Exploit / POC
Canary Labs Trend Link ActiveX Control 'SaveToFile()' Insecure Method Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Canary Labs Trend Link ActiveX Control 'SaveToFile()' Insecure Method Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Canary Labs Trend Link ActiveX Control 'SaveToFile()' Insecure Method Vulnerability
References:
References:
- Microsoft Support Document 240797 (Microsoft)
- TrendLink Homepage (Canary Labs)
- ICSA-13-098-01 CANARY LABS, INC. TREND LINK INSECURE ACTIVEX CONTROL METHOD (ICS-CERT)