|
|
|
Vulnerability Note VU#788860Trend Micro OfficeScan Management Console ActiveX control format string vulnerabilityOverviewThe Trend Micro OfficeScan Management Console ActiveX control, AtxConsole, contains a format string vulnerability. This vulnerability may be exploited by an attacker to execute arbitrary code, or create a denial-of-service condition.I. DescriptionTrend Micro's OfficeScan product includes a web-based management console. The management console uses an ActiveX control, which in turn interacts with CGI applications on the OfficeScan server. This ActiveX control, which has a CLSID of {8990AFAD-D352-42AC-A72F-A660BBF6E209}, contains a format string vulnerability.Note that any system that has used the vulnerable control in the past may be vulnerable.
Trend Micro has addressed this issue in OfficeScan 7.3 Patch 1.
Disable ActiveX Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this vulnerability. Instructions for disabling ActiveX in the Internet Zone can be found in the "Securing Your Web Browser" document. Systems Affected
References
This report is based on information from Deral Heiland of Layered Defense. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||