Description
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1) cgiChkMasterPwd.exe, (2) policyserver.exe as reachable through cgiABLogon.exe, and other vectors.
Affected products
- Trend Micro / officescan_corporate_edition7.3_patch3_build1314
Exploits & proofs of concept
- exploit-dbTrend Micro OfficeScan - Remote Stack Buffer Overflow (Metasploit)by Metasploit
- exploit-dbTrend Micro OfficeScan - Buffer Overflow (Denial of Service) (PoC)by Luigi Auriemma
Updated 16m ago · 8 sources