Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows >> Trend Micro officescan remote buffer overflow vulnerability


Vulnerability Assessment Details

Trend Micro officescan remote buffer overflow vulnerability

Vulnerability Assessment Summary
Checks if vulnerable version Trend Micro Office scan is installed

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote Windows host is affected by a remote buffer overflow
vulnerability.

Description :

The remote host is running Trend Micro Antivirus, a commercial
anti-virus software package for Windows. The remote version of the
installed antivirus is vulnerable to a remote buffer overflow
vulnerability. The issue exists due a vulnerability in the ActiveX
control installed by the OfficeScan server during a web install of the
OfficeScan clients. The clients cache this ActiveX control which can
be exploited by a malicious website. The attacker can trigger this
issue by enticing a user to click on a malicious link or sending the
the link in an email and urging the user to click on it. Successful
exploitation of this issue might result in arbitrary code execution.

See also:

http://www.nessus.org/u?62e87258
http://www.nessus.org/u?14064dc2
http://www.nessus.org/u?2b2f278b
http://www.nessus.org/u?ad4ca3ae

Solution :

Apply the security patch released by the vendor.

Network Security Threat Level:

High / CVSS Base Score : 8.0
(AV:R/AC:H/Au:NR/C:C/I:C/A:C/B:N)

Networks Security ID: 22585

Vulnerability Assessment Copyright: This script is Copyright (C) 2007 Tenable Network Security, Inc

Cables, Connectors


Dell PowerEdge R720 Server - 2x8c CPU,256Gb RAM, 128Gb SSD/3x600Gb SAS, Proxmox picture

Dell PowerEdge R720 Server - 2x8c CPU,256Gb RAM, 128Gb SSD/3x600Gb SAS, Proxmox

$360.00



DELL PowerEdge R730 Server 2x E5-2690v3 2.6GHz =24 Cores 32GB H730 4xRJ45 picture

DELL PowerEdge R730 Server 2x E5-2690v3 2.6GHz =24 Cores 32GB H730 4xRJ45

$274.00



Dell PowerEdge R620 Server 2x E5-2660 v1 2.2GHz 16 Cores 256GB RAM 1x 300GB HDD picture

Dell PowerEdge R620 Server 2x E5-2660 v1 2.2GHz 16 Cores 256GB RAM 1x 300GB HDD

$89.99



Dell PowerEdge R720XD Xeon E5-2680 V2 2.8GHz 20 Cores 256GB RAM 12x4TB picture

Dell PowerEdge R720XD Xeon E5-2680 V2 2.8GHz 20 Cores 256GB RAM 12x4TB

$510.00



Dell PowerEdge R730XD 28 Core Server 2X Xeon E5-2680 V4 H730 128GB RAM No HDD picture

Dell PowerEdge R730XD 28 Core Server 2X Xeon E5-2680 V4 H730 128GB RAM No HDD

$389.99



Dell PowerEdge R730, 2 sinks, SystemBoard, 8 trays,H330,Idrac 8 exp, 2x750w Psu picture

Dell PowerEdge R730, 2 sinks, SystemBoard, 8 trays,H330,Idrac 8 exp, 2x750w Psu

$135.00



DELL POWEREDGE T430 SERVER W/ DUAL XEON E5-2609 CPU & 16GB MEMORY picture

DELL POWEREDGE T430 SERVER W/ DUAL XEON E5-2609 CPU & 16GB MEMORY

$329.00



Dell PowerEdge T330 E3-1240v5 3.5GHz 3.5

Dell PowerEdge T330 E3-1240v5 3.5GHz 3.5" 8-Bay 8GB PERC H330 Server Tower

$200.00



DELL PowerEdge R630 8SFF Server 2x E5-2680v3 2.5GHz =24 Cores 32GB H730 4xRJ45 picture

DELL PowerEdge R630 8SFF Server 2x E5-2680v3 2.5GHz =24 Cores 32GB H730 4xRJ45

$240.00



Dell Poweredge R730xd 2.5in 2x E5-2690 v3 2.6ghz 24-Cores  64gb  H730  2x 750w picture

Dell Poweredge R730xd 2.5in 2x E5-2690 v3 2.6ghz 24-Cores 64gb H730 2x 750w

$189.99



Discussions

No Discussions have been posted on this vulnerability.