First published: Tue Dec 23 2008(Updated: )
The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary library file onto a client system via a "custom update server" argument. NOTE: this can be leveraged for code execution by writing to a Startup folder.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro HouseCall | =6.6 | |
Trend Micro HouseCall | =6.6.0.1278 | |
Trend Micro HouseCall | =6.51.0.1028 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.