// For flags

CVE-2007-0325

Trend Micro OfficeScan - Client ActiveX Control Buffer Overflow

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.

Múltiples desbordamientos de búfer en el control ActiveX Trend Micro OfficeScan Web-Deployment SetupINICtrl en OfficeScanSetupINI.dll, como ha sido usado en OfficeScan 7.0 anterior a Build 1344, OfficeScan 7.3 anetrior a Build 1241, y Client / Server / Messaging Security 3.0 anterior a Build 1197, permite a atacantes remotos ejecutar código de su elección mediante un documento HTML artesanal.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-01-17 CVE Reserved
  • 2007-02-20 CVE Published
  • 2010-05-09 First Exploit
  • 2024-07-15 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Trend Micro
Search vendor "Trend Micro"
Client-server-messaging Security
Search vendor "Trend Micro" for product "Client-server-messaging Security"
3.0
Search vendor "Trend Micro" for product "Client-server-messaging Security" and version "3.0"
-
Affected
Trend Micro
Search vendor "Trend Micro"
Officescan Corporate Edition
Search vendor "Trend Micro" for product "Officescan Corporate Edition"
7.0
Search vendor "Trend Micro" for product "Officescan Corporate Edition" and version "7.0"
-
Affected
Trend Micro
Search vendor "Trend Micro"
Officescan Corporate Edition
Search vendor "Trend Micro" for product "Officescan Corporate Edition"
7.3
Search vendor "Trend Micro" for product "Officescan Corporate Edition" and version "7.3"
-
Affected