VDB
CVE-2008-2434
CVE-2008-2434
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary library file onto a client system via a "custom update server" argument. NOTE: this can be leveraged for code execution by writing to a Startup folder.
EPSS 29.33% · 96.7th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
29.33%
96.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| trend_micro | housecall | 6.6, 6.6.0.1278, 6.51.0.1028 |
| n/a | n/a | n/a |
Timeline
- Dec 23, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- VU#541025 third-party-advisory
- housecall-library-code-execution(47524) vdb
- 4802 third-party-advisory
- 31337 third-party-advisory
- ADV-2008-3464 vdb
- 20081222 Secunia Research: Trend Micro HouseCall ActiveX Control Arbitrary Code Execution mailing-list
- http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1038646&id=EN-1038646 url
- http://secunia.com/secunia_research/2008-32/ url
- 32965 vdb
- 50941 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-2434 advisory
- http://secunia.com/secunia_research/2008-32 url