CVE-2008-2434

EUVD-2008-2429
The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary library file onto a client system via a "custom update server" argument.  NOTE: this can be leveraged for code execution by writing to a Startup folder.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
trend_microhousecall
6.6
trend_microhousecall
6.6.0.1278
trend_microhousecall
6.51.0.1028
𝑥
= Vulnerable software versions