exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

AD20071211.txt

AD20071211.txt
Posted Dec 12, 2007
Authored by Sowhat | Site nevisnetworks.com

There is a vulnerability in TrendMicro Antivirus, which allows an attacker to escalate to SYSTEM privileges, cause a denial of service, or potentially execute arbitrary code.

tags | advisory, denial of service, arbitrary
SHA-256 | cbbe329974518f2285471fa2997e42aa2c2f547dfec54c5cfd80f713192ff19c

AD20071211.txt

Change Mirror Download
TrendMicro AntiVirus UUE Processing Vulnerability


Sowhat of Nevis Labs
http://www.nevisnetworks.com
http://secway.org/advisory/AD20071211.txt


Vendor:
TrendMicro


Affected:
TrendMicro Antivirus prior to PccScan.dll build 1451
This vulnerability has been confirmed on TrendMicro Antivirus and
Antispyware 20008
(PccScan.dll build 1450).



Details:

There is a vulnerability in TrendMicro Antivirus, which allows an attacker
to escalate to SYSTEM privilege, Denial of service, or potential execute
arbitrary
code (not confirmed yet).

While decoding the .uue file., TrendMicro Antivirus will create a .zip file,

by manipulating the .uue file, we can make the TrendMicro AV generate a .zip
file
which contains a long file name.

Due to the incorrect usage of wcsncpy_s() API while PccScan.dll is trying to
copy
this long file name into a static buffer, the SfCtlCom.exe will crash.

Because SfCtlCom.exe is running under SYSTEM privilege, local privilege is
possible
in some cases, e.g. there is a just-in-time debugger presented.

The remote exploitability has not been confirmed yet.

And also, According to the vendor:
"malformed UUE is not necessary, just a malformed zip file is enough"

So this vulnerability should be called as a ".ZIP processing vulnerability",
not .UUE

The vulnerability can be exploited remotely, by sending Email or convince
the
victim visit attacker controlled website. Or can be exploited locally to
gain the
SYSTEM privilege.


Vendor Response:

2007.11.12 Vendor notified through several email address.
2007.11.13 Auto-Response from the support.
2007.11.13 Get the right person by sending emails to FD
2007.11.23 Patch available
2007.12.05 Patch planned on 5th, Dec
2007.12.06 Patch delayed to 7th, Dec
2007.12.11 Patch released by the vendor
2007.12.11 Advisory released.

Reference:
1. http://esupport.trendmicro.com/support/viewxml.do?ContentID=1036464
2. http://secway.org/advisory/AD20071116.txt
3. http://groups.google.com/group/vulnhashdb



--
Sowhat
http://secway.org
"Life is like a bug, Do you know how to exploit it ?"
Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close