CVE-2008-2435: Use After Free
Published Dec 23, 2008
·Updated
Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in HousecallActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.
Affected Software
2 affected components
Trend Micro HouseCall=6.6.0.1278
Trend Micro HouseCall=6.51.0.1028
Event History
Dec 23, 2008
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2435?
CVE-2008-2435 is considered critical due to the potential for remote code execution.
2
How do I fix CVE-2008-2435?
To fix CVE-2008-2435, update the Trend Micro HouseCall ActiveX control to the latest version available.
3
What software versions are affected by CVE-2008-2435?
CVE-2008-2435 affects Trend Micro HouseCall versions 6.51.0.1028 and 6.6.0.1278.
4
How can CVE-2008-2435 be exploited?
CVE-2008-2435 can be exploited through a crafted notifyOnLoadNative callback function that triggers a use-after-free condition.
5
Are there any known exploits for CVE-2008-2435?
Yes, CVE-2008-2435 has known exploits that allow attackers to execute arbitrary code remotely.