Trend Micro OfficeScan CGI programs POST request buffer overflow
Added: 10/31/2008CVE: CVE-2008-3862
BID: 31859
OSVDB: 49275
Background
Trend Micro OfficeScan is a centralized virus and security scan management system.Problem
A buffer overflow vulnerability allows remote attackers to execute arbitrary commands by sending specially crafted HTTP POST requests to various CGI programs included in Trend Micro OfficeScan.Resolution
Apply one of the patches referenced in Secunia advisory 32005.References
http://secunia.com/secunia_research/2008-40/Limitations
Exploit works on Trend Micro OfficeScan 7.3 Patch5 on Windows 2000 SP4, Windows Server 2003 SP2 without DEP, and Windows Server 2003 SP2 with patch KB933729 with DEP.Platforms
Windows 2000 / Windows Server 2003 without DEPWindows Server 2003
Back to exploit index