First published: Tue Oct 03 2006(Updated: )
Format string vulnerability in the ActiveX control (ATXCONSOLE.OCX) in TrendMicro OfficeScan Corporate Edition (OSCE) before 7.3 Patch 1 allows remote attackers to execute arbitrary code via format string identifiers in the "Management Console's Remote Client Install name search".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan XG | =corporate_7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5157 has a high severity rating due to the potential for remote code execution.
To fix CVE-2006-5157, update TrendMicro OfficeScan Corporate Edition to version 7.3 Patch 1 or later.
CVE-2006-5157 affects TrendMicro OfficeScan Corporate Edition prior to version 7.3 Patch 1.
CVE-2006-5157 is a format string vulnerability that can be exploited by attackers.
Yes, CVE-2006-5157 can be exploited remotely through malicious format string identifiers.