First published: Tue Feb 20 2007(Updated: )
Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Client Server Messaging Security | =3.0 | |
Trend Micro OfficeScan Corporate Edition | =7.0 | |
Trend Micro OfficeScan Corporate Edition | =7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0325 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2007-0325, update the affected Trend Micro OfficeScan and Client/Server/Messaging Security versions to the latest patched builds.
CVE-2007-0325 affects Trend Micro OfficeScan versions 7.0 before Build 1344, 7.3 before Build 1241, and Client/Server/Messaging Security version 3.0 before Build 1197.
CVE-2007-0325 is associated with buffer overflow vulnerabilities that can be exploited remotely.
Users of the affected versions of Trend Micro OfficeScan and Client/Server/Messaging Security may be impacted by CVE-2007-0325.