"Protect your desktops, laptops, and file servers with OfficeScan, comprehensive security against today's complex, blended threats and Web-based attacks." Secunia Research has discovered a vulnerability in Trend Micro OfficeScan, which can be exploited by malicious people to compromise a vulnerable system.
A boundary error in cgiRecvFile.exe can be exploited to cause a stack-based buffer overflow via an HTTP request with a specially crafted, overly long "ComputerName" parameter. The "TempFileName", "NewFileSize", and "Verify" parameters must also be manipulated to exploit the vulnerability.
Successful exploitation allows execution of arbitrary code.
Solution:
Apply patches available from the vendor.
Time Table:
02/09/2008 - Vendor notified.
02/09/2008 - Vendor response.
12/09/2008 - Public disclosure.