First published: Wed Apr 16 2008(Updated: )
The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote attackers to execute arbitrary code via crafted function arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CA ARCserve Backup for Laptops and Desktops | =r11.5 | |
CA Desktop and Server Management | =r11.1 | |
CA Desktop and Server Management | =r11.2 | |
CA Desktop and Server Management | =r11.2a | |
CA Desktop and Server Management | =r11.2c1 | |
CA Desktop and Server Management | =r11.2c2 | |
Broadcom Desktop Management Suite | =r11.2 | |
Broadcom Desktop Management Suite | =r11.2a | |
Broadcom Desktop Management Suite | =r11.2c1 | |
Broadcom Desktop Management Suite | =r11.2c2 | |
CA Unicenter DSM Agent | =r11.1 | |
CA Unicenter DSM Agent | =r11.2 | |
CA Unicenter DSM Agent | =r11.2a | |
CA Unicenter DSM Agent | =r11.2c1 | |
CA Unicenter DSM Agent | =r11.2c2 | |
Unicenter Desktop Management Bundle | =r11.1 | |
Unicenter Desktop Management Bundle | =r11.2 | |
Unicenter Desktop Management Bundle | =r11.2a | |
Unicenter Desktop Management Bundle | =r11.2c1 | |
Unicenter Desktop Management Bundle | =r11.2c2 | |
CA Unicenter Remote Control | =r11.1 | |
CA Unicenter Remote Control | =r11.2 | |
CA Unicenter Remote Control | =r11.2a | |
CA Unicenter Remote Control | =r11.2c1 | |
CA Unicenter Remote Control | =r11.2c2 | |
Broadcom Unicenter Service Delivery | =r11.1 | |
Broadcom Unicenter Service Delivery | =r11.2 | |
Broadcom Unicenter Service Delivery | =r11.2a | |
Broadcom Unicenter Service Delivery | =r11.2c1 | |
Broadcom Unicenter Service Delivery | =r11.2c2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1786 has a severe impact due to the potential for remote code execution through the affected ActiveX control.
To fix CVE-2008-1786, update the affected CA products to their latest patches provided by Broadcom.
CVE-2008-1786 affects multiple CA products including BrightStor ARCServe Backup, Desktop Management Suite, and Unicenter Software Delivery, among others.
The risk associated with CVE-2008-1786 includes unauthorized access and execution of potentially harmful code on vulnerable systems.
A possible workaround for CVE-2008-1786 is to disable the ActiveX control in Internet Explorer until an update can be applied.