>> CA eTrust Intrusion Detection "caller.dll" ActiveX Control Code Execution Vulnerability
Title : CA eTrust Intrusion Detection "caller.dll" ActiveX Control Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-2640 CVE ID : CVE-2007-3302
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-25
Technical Description
A vulnerability has been identified in CA eTrust Intrusion Detection, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an error in the "Caller.dll" ActiveX control that contains various scriptable functions allowing a web page to load arbitrary DLLs and call their exports with controlled parameters, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a malicious web page.