Vulnerabilities > CVE-2007-2864

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
broadcom
ca
critical
exploit available
metasploit

Summary

Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

Exploit-Db

descriptionCA Antivirus Engine CAB Buffer Overflow. CVE-2007-2864. Local exploit for windows platform
idEDB-ID:16677
last seen2016-02-02
modified2010-11-11
published2010-11-11
reportermetasploit
sourcehttps://www.exploit-db.com/download/16677/
titleCA Antivirus Engine CAB Buffer Overflow

Metasploit

descriptionThis module exploits a stack buffer overflow in CA eTrust Antivirus 8.1.637. By creating a specially crafted CAB file, an attacker may be able to execute arbitrary code.
idMSF:EXPLOIT/WINDOWS/FILEFORMAT/CA_CAB
last seen2020-03-10
modified2020-01-15
published2009-08-27
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2864
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/fileformat/ca_cab.rb
titleCA Antivirus Engine CAB Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83164/ca_cab.rb.txt
idPACKETSTORM:83164
last seen2016-12-05
published2009-11-26
reporterMC
sourcehttps://packetstormsecurity.com/files/83164/CA-Antivirus-Engine-CAB-Buffer-Overflow.html
titleCA Antivirus Engine CAB Buffer Overflow

Saint

bid24330
descriptionCA Antivirus engine CAB handling buffer overflow
idmisc_av_cacab
osvdb35245
titleca_antivirus_cab
typeclient