Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Trend Micro OfficeScan ObjRemoveCtrl ActiveX Control Buffer Overflow Vulnerability |
|---|---|
| Date: | Mon, 28 Jul 2008 13:14:37 -0400 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Who: Trend Micro http://www.trendmicro.com What: OfficeScan 7.3 build 1343(Patch 4) and older http://www.trendmicro.com/download/product.asp?productid=5 How: OfficeScan's Web Console utilizes several ActiveX controls when deploying the product through the web interface. One of these controls, objRemoveCtrl, is vulnerable to a stack-based buffer overflow when embedded in a webpage. The one caveat to this issue is that the control must be embedded in such a way that it CAN be visible, i.e. obj = new ActiveXObject() will not work. The issue lies in the code that is used to display certain properties and their values on the control when it is embedded in a page. OfficeScanRemoveCtrl.dll, version 7.3.0.1020 {5EFE8CB1-D095-11D1-88FC-0080C859833B} Commonly located: systemdrive\Windows\Downloaded Program Files CAB location on server: officescan install path\OfficeScan\PCCSRV\Web_console\ClientInstall\RemoveCtrl.cab The following properties are vulnerable: HttpBased LatestPatternServer LatestPatternURL LocalServerPort MasterDirectory MoreFiles PatternFilename ProxyLogin ProxyPassword ProxyPort ProxyServer RegistryINIFilename Server ServerIniFile ServerPort ServerSubDir ServiceDisplayName ServiceFilename ServiceName ShellExtensionFilename ShortcutFileList ShortcutNameList UninstallPassword UnloadPassword UseProxy Workaround: Set the killbit for the affected control. See http://support.microsoft.com/KB/240797 Fix: As stated below, reportedly there are patches for this issue, however, I have been able to exploit this issue in a test environment running OfficeScan 7.3 patch 4(latest available patch). Timeline: 06/27/2008 -> Vulnerability discovered and reported to iDefense 07/02/2008 <- Request for further information 07/16/2008 <- iDefense states that patches exist which resolve this issue 07/16/2008 -> Request clarification regarding which patches resolve this issue. No response 07/20/2008 -> Follow up regarding patches. No response 07/28/2008 - Disclosure -----BEGIN PGP SIGNATURE----- Charset: UTF8 Version: Hush 3.0 Note: This signature can be verified at https://www.hushtools.com/verify wpwEAQECAAYFAkiN/hsACgkQi04xwClgpZiTrQP+M9MX2MgvLk+HaMgmYghBRQaTG89M bb0RywlP2UY6/P9qIk0W3AfI1UsVZUPcTduvo+/BKIR7s5M/m+VTa74lEMH5FHQ17QZ6 tAAKI/TYGl7YWG/+4Zj7n8hpjIhT7AahtjbASTwUxSv3pFet/9DMM9nrCXolR0+bsajy nJzOnmg= =kQK+ -----END PGP SIGNATURE----- -- Discover hidden treasures! Click now for a new metal detector! http://tagline.hushmail.com/fc/Ioyw6h4c5jwe35WKO72pIZH3J68Qr1p1BCzmhxGSAr9zTajkwjyaNq/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | how to request a cve id?, xpzhang |
|---|---|
| Next by Date: | Re: [Full-disclosure] how to request a cve id?, n3td3v |
| Previous by Thread: | how to request a cve id?, xpzhang |
| Next by Thread: | [Full-disclosure] [USN-630-1] ffmpeg vulnerability, Kees Cook |
| Indexes: | [Date] [Thread] [Top] [All Lists] |