Trend Micro OfficeScan contains a security flaw

Feb 16, 2007 14:43 GMT  ·  By

When our computers are infected with a powerful virus that is able to harm the system and damage all the important files, we usually install a well-known antivirus solution to clean the hard-disk and protect the data stored on the computer. What happens when the antivirus is not able to disinfect the computer or if it contains several errors that prevent it from cleaning the system? The files are damaged by the infection, the operating system is affected and the loading times are increased. What about the vulnerabilities discovered in the security solutions meant to protect the computer? Well, this is one of the most dangerous situations because the antivirus is converting from our friend into one of the biggest enemies.

Trend Micro OfficeScan is one of these antivirus solutions that are affected by security flaws but let me hope that it will not become a powerful enemy for the computer. Security company Secunia rated the flaw as highly critical, mentioning the only version of the application is Trend Micro OfficeScan Corporate Edition 7.x.

"A vulnerability has been reported in Trend Micro OfficeScan, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error within an unspecified ActiveX control on an OfficeScan client. This can be exploited to cause a buffer overflow when a user e.g. visits a specially crafted web site. Successful exploitation allows execution of arbitrary code, but requires that OfficeScan client was installed using web deployment," Secunia reported.

If you want to keep Trend Micro OfficeScan as your computer's friend and avoid a successful exploitation of the vulnerability, you should install the patches especially released by the developer of the antivirus to fix the security flaw. The patch for OfficeScan 7.0 is available at this link, while the fix for OfficeScan 7.3 can be download from this page (both files are stored on Trend Micro's servers).