Vulnerable Systems:
* Trendmicro OfficeScan Corporate Edition version 7.3
Immune Systems:
* Trendmicro OfficeScan Corporate Edition version 7.3 with Patch 1
The vulnerability is due to improper processing of format strings within OfficeScan Management consoles ActiveX Control "ATXCONSOLE.OCX". Specially crafted format string passed back to the Management consoles Remote Client Install name search would allow access to the process stack.
If successfully exploited, this could allow the user to execute code of the attackers choice on the system running the ActiveX management Console.