vendor:
Internet Security Pro 2010
by:
Shahin, Abysssec
9,3
CVSS
CRITICAL
Remote Code Execution
119
CWE
Product Name: Internet Security Pro 2010
Affected Version From: 17.50.0.1366
Affected Version To: 17.50.0.1366
Patch Exists: YES
Related CWE: CVE-2010-0478
CPE: a:trend_micro:internet_security_pro_2010
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2010
Trend Micro Internet Security Pro 2010 ActiveX extSetOwner Remote Code Execution
A vulnerability in Trend Micro Internet Security Pro 2010 ActiveX extSetOwner allows remote attackers to execute arbitrary code via a crafted web page. The vulnerability is due to a boundary error when handling the extSetOwner method. An attacker can exploit this vulnerability to execute arbitrary code in the context of the user running the affected application. Successful exploitation of this vulnerability could result in complete compromise of the affected system.
Mitigation:
Upgrade to the latest version of Trend Micro Internet Security Pro 2010.