9.3
CVSSv2

CVE-2008-1472

Published: 24/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote malicious users to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

Vulnerable Product Search on Vulmon Subscribe to Product

computer associates brightstor arcserve backup laptops desktops 11.5

unicenter asset management r11.1

unicenter desktop management bundle r11.2

unicenter software delivery r11.1

computer associates unicenter dsm r11 list control atx 11.2.3.1895

unicenter desktop management bundle r11.1

unicenter remote control r11.2

computer associates desktop management suite r11.1

unicenter asset management r11.2

unicenter remote control r11.1

unicenter software delivery r11.2

computer associates desktop management suite r11.2

Exploits

## # $Id: ca_brightstor_addcolumnrb 9525 2010-06-15 07:18:08Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' ...
<HTML> <!-- CA BrightStor ARCserve Backup r115 AddColumn() 0day ActiveX Remote Buffer Overflow Exploit Bug discovered by Krystian Kloskowski (h07) <h07@interiapl> Tested on: - CA BrightStor ARCserve Backup r115 (ftp://ftpcacom/priv/trial/BABr11/BABLDr115/BABLDr115zip) - IE 6 - XP SP2 Polish Details: Filename: CA\DSM\bin\Li ...