vendor:
OfficeScan
by:
e.b.
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: OfficeScan
Affected Version From: 7.3
Affected Version To: 7.3.0.1020
Patch Exists: Yes
Related CWE: N/A
CPE: a:trend_micro:officescan
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP
2008
Trend Micro OfficeScan ObjRemoveCtrl ActiveX Control Buffer Overflow Exploit
This exploit is related to the Trend Micro OfficeScan ObjRemoveCtrl ActiveX Control Buffer Overflow vulnerability. It was written by e.b. and tested on Windows XP SP2(fully patched) English, IE6 + IE7, OfficeScan 7.3 patch 4, OfficeScanRemoveCtrl.dll version 7.3.0.1020. The control is installed when you install OfficeScan through the server web console. This was fixed in OfficeScan 8.x(uses strcpy_s which throws INVALID_PARAMETER, still crashes the browser though).
Mitigation:
Upgrade to OfficeScan 8.x or later.