CVE-2008-3862
Stack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 Patch 1 before build 3110, allows remote attackers to execute arbitrary code via an HTTP POST request…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 Patch 1 before build 3110, allows remote attackers to execute arbitrary code via an HTTP POST request containing crafted form data, related to "parsing CGI requests."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 18.41% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- trend micro/officescan
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/32005Patch, Vendor Advisory
- http://secunia.com/secunia_research/2008-40/Vendor Advisory
- http://securityreason.com/securityalert/4489
- http://www.securityfocus.com/archive/1/497650/100/0/threaded
- http://www.securityfocus.com/bid/31859
- http://www.securitytracker.com/id?1021093
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_7.3_CriticalPatch_B1374_readme.txtPatch
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_sp1p1_CriticalPatch_B3110_readme.txtPatch
- http://www.vupen.com/english/advisories/2008/2892
- http://secunia.com/advisories/32005Patch, Vendor Advisory
- http://secunia.com/secunia_research/2008-40/Vendor Advisory
- http://securityreason.com/securityalert/4489
- http://www.securityfocus.com/archive/1/497650/100/0/threaded
- http://www.securityfocus.com/bid/31859
- http://www.securitytracker.com/id?1021093
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_7.3_CriticalPatch_B1374_readme.txtPatch
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_sp1p1_CriticalPatch_B3110_readme.txtPatch
- http://www.vupen.com/english/advisories/2008/2892
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.