In association with heise online

2 October 2006, 16:07

Patch closes three holes in OfficeScan Corporate Edition 7.3

According to a security advisory published by security provider Layered Security, an update for OfficeScan Corporate Addition 7.3 released a few days ago by Trend Micro, remedies a security hole in an ActiveX control. According to the bulletin, a weak point in the format string in the ATXCONSOLE.OCX control for remote management is the cause of the problem; attackers can use it to gain control of a PC.

But there is no mention of this problem in Trend Micro's change log. However, the log does describe a buffer overflow in Wizard.exe (under \PCCSRV\Web_console\RemoteInstallCGI\) and CgiRemoteInstall.exe (under \PCCSRV\Web_console\RemoteInstallCGI\). The vendor does not say whether these overflows can be used for attacks. Whatever the case, users should install the update as quickly as possible.

See also:

(trk)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit







The H open source

The H Security

The H Internet Toolkit