Trend, McAfee vulnerabilities disclosed

ActiveX and ePO flaws covered by patches.

Trend Micro's flagship OfficeScan Corporate Edition 7.3 has suffered a vulnerability, allowing code execution from the local network.

VB100

The flaw, in an ActiveX control used by the client management system, was originally reported by Layered Defense, whose advisory is here. The problem was reported to Trend some months ago, and the announcement has been made some time after Trend released a patch to fix the issue, available from here.

Layered Defense has rated the problem 'medium risk', while Secunia, whose alert is here, calls it 'moderately critical'.

Also 'moderately critical' are holes in McAfee's ePolicy Orchestrator 3.5 and ProtectionPilot 1.1, also known about for some time and now patched. The buffer overflow problem could allow system access to an attacker within the local network. The Secunia alert is here.

03 October 2006

Tags: virus  

 del.icio.us  digg this! digg this

Quick Links

Poll
Does your company allow you to use a personal laptop/mobile device to access company resources?
Yes, it's allowed
Yes, it's actively encouraged
No
I don't know
Leave a comment
View 1 comment

Jobs Recruit Sidebar

Jobs
In Virus Bulletin's jobs pages among others:

Virus Bulletin currently has 225,202 registered users.