Lucene search

K
cveCertccCVE-2007-0325
HistoryFeb 20, 2007 - 5:28 p.m.

CVE-2007-0325

2007-02-2017:28:00
CWE-119
certcc
web.nvd.nist.gov
33
cve-2007-0325
buffer overflows
trend micro officescan
activex
officescan 7.0
officescan 7.3
client/server/messaging security 3.0
remote code execution
html document

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.818

Percentile

98.4%

Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.

Affected configurations

Nvd
Node
trend_microclient-server-messaging_securityMatch3.0
OR
trend_microofficescan_corporate_editionMatch7.0
OR
trend_microofficescan_corporate_editionMatch7.3
VendorProductVersionCPE
trend_microclient-server-messaging_security3.0cpe:2.3:a:trend_micro:client-server-messaging_security:3.0:*:*:*:*:*:*:*
trend_microofficescan_corporate_edition7.0cpe:2.3:a:trend_micro:officescan_corporate_edition:7.0:*:*:*:*:*:*:*
trend_microofficescan_corporate_edition7.3cpe:2.3:a:trend_micro:officescan_corporate_edition:7.3:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.818

Percentile

98.4%