CVE-2008-2437
Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long ComputerName parameter.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 6.67% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- trend micro/client-server-messaging security · trend micro/officescan
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/31342Vendor Advisory
- http://secunia.com/secunia_research/2008-35/Vendor Advisory
- http://securityreason.com/securityalert/4263
- http://www.securityfocus.com/archive/1/496281/100/0/threaded
- http://www.securityfocus.com/bid/31139Patch
- http://www.securitytracker.com/id?1020860
- http://www.trendmicro.com/ftp/documentation/readme/CSM_3.6_OSCE_7.6_Win_EN_CriticalPatch_B1195_readme.txt
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_7.3_Win_EN_CriticalPatch_B1367_readme.txt
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Patch1_Win_EN_CriticalPatch_B3060_readme.txt
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Win_EN_CriticalPatch_B2424_readme.txt
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_Win_EN_CriticalPatch_B1361_readme.txt
- http://www.vupen.com/english/advisories/2008/2555
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45072
- http://secunia.com/advisories/31342Vendor Advisory
- http://secunia.com/secunia_research/2008-35/Vendor Advisory
- http://securityreason.com/securityalert/4263
- http://www.securityfocus.com/archive/1/496281/100/0/threaded
- http://www.securityfocus.com/bid/31139Patch
- http://www.securitytracker.com/id?1020860
- http://www.trendmicro.com/ftp/documentation/readme/CSM_3.6_OSCE_7.6_Win_EN_CriticalPatch_B1195_readme.txt
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_7.3_Win_EN_CriticalPatch_B1367_readme.txt
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Patch1_Win_EN_CriticalPatch_B3060_readme.txt
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Win_EN_CriticalPatch_B2424_readme.txt
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_Win_EN_CriticalPatch_B1361_readme.txt
- http://www.vupen.com/english/advisories/2008/2555
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45072
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.