Use-After-Free Remote Code Execution in Trend Micro HouseCall ActiveX Control
CVE-2008-2435

Currently unrated

Key Information:

Status
Vendor
CVE Published:
23 December 2008

What is CVE-2008-2435?

A use-after-free vulnerability exists in the Trend Micro HouseCall ActiveX control, specifically in the notifyOnLoadNative callback function. This flaw allows remote attackers to craft specific inputs that can lead to arbitrary code execution, potentially compromising the system's integrity and security. Users of affected versions are at risk if proper mitigations are not implemented.

References

EPSS Score

23% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.