Overview
The Trend Micro OfficeScan Management Console ActiveX control, AtxConsole, contains a format string vulnerability. This vulnerability may be exploited by an attacker to execute arbitrary code, or create a denial-of-service condition.
Description
Trend Micro's OfficeScan product includes a web-based management console. The management console uses an ActiveX control, which in turn interacts with CGI applications on the OfficeScan server. This ActiveX control, which has a CLSID of {8990AFAD-D352-42AC-A72F-A660BBF6E209}, contains a format string vulnerability. Note that any system that has used the vulnerable control in the past may be vulnerable. |
Impact
By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause Internet Explorer (or the program using the WebBrowser control) to crash. |
Solution
Apply an update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This report is based on information from Deral Heiland of Layered Defense.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-5157 |
Severity Metric: | 3.85 |
Date Public: | 2006-10-02 |
Date First Published: | 2006-10-11 |
Date Last Updated: | 2006-11-08 13:18 UTC |
Document Revision: | 45 |