Trend Micro extSetOwner Method Remote Code Execution

Strike ID:
E12-5ql01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
2
Year:
2012

Description

This strike exploits a vulnerability in Trend Micro's Internet Security Pro 2010. When calling the extSetOwner method, a user can use memory at a specific address.This value can then later be used as a function pointer to access arbitrary memory addresses or execute code.

CVE