Vulnerabilities > CVE-2008-2435 - Resource Management Errors vulnerability in Trend Micro Housecall 6.51.0.1028/6.6.0.1278

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
trend-micro
CWE-399
critical

Summary

Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.

Vulnerable Configurations

Part Description Count
Application
Trend_Micro
2

Common Weakness Enumeration (CWE)

Seebug

bulletinFamilyexploit
descriptionCVE(CAN) ID: CVE-2008-2435 HouseCall是用于检查计算机是否被病毒、间谍软件感染的应用程序。 HouseCall ActiveX控件(Housecall_ActiveX.dll)中存在使用后释放漏洞,如果用户受骗访问了包含有特制notifyOnLoadNative()回调函数的网页的话,就会引用之前已释放的内存。成功利用这个漏洞允许在用户机器上执行任意代码。 Trend Micro HouseCall Server Edition - 6.6 Trend Micro ----------- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1038646&id=EN-1038646 target=_blank>http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1038646&id=EN-1038646</a>
idSSV:4579
last seen2017-11-19
modified2008-12-23
published2008-12-23
reporterRoot
titleTrend Micro HouseCall notifyOnLoadNative()函数任意代码执行漏洞