>> Trend Micro OfficeScan "ATXCONSOLE.OCX" ActiveX Format String Vulnerability
Title : Trend Micro OfficeScan "ATXCONSOLE.OCX" ActiveX Format String Vulnerability VUPEN ID : VUPEN/ADV-2006-3870 CVE ID : GENERIC-MAP-NOMATCH
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-03
Technical Description
A vulnerability has been identified in Trend Micro OfficeScan, which could be exploited by attackers to take complete control of an affected system. This flaw is due to a format string error in the "ATXCONSOLE.OCX" ActiveX control when handling a specially crafted parameter passed to the Management Console's Remote Client Install name search, which could be exploited by attackers to cause a denial of service or execute arbitrary commands.