CVE-2007-0325

Trend Micro OfficeScan and Client/Server/Messaging Security - Remote Code Execution via Crafted HTML Document

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-0325. PoCs published by Metasploit, MC, including Metasploit module exploits/windows/browser/trendmicro_officescan.

AI-analyzed exploit summary This exploit targets a stack buffer overflow in Trend Micro OfficeScan Corporate Edition 7.3 via the CgiOnUpdate() method in OfficeScanSetupINI.dll. It delivers a payload through a malicious HTML page with an embedded ActiveX control.

Description

Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16535

This exploit targets a stack buffer overflow in Trend Micro OfficeScan Corporate Edition 7.3 via the CgiOnUpdate() method in OfficeScanSetupINI.dll. It delivers a payload through a malicious HTML page with an embedded ActiveX control.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Trend Micro OfficeScan Corporate Edition 7.3
No auth needed
Prerequisites: Victim must visit a malicious web page · ActiveX controls must be enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/trendmicro_officescan.rb

This Metasploit module exploits a stack buffer overflow in Trend Micro OfficeScan Corporate Edition 7.3 via an overly long string passed to the CgiOnUpdate() method in OfficeScanSetupINI.dll. It delivers a payload through a malicious HTML page with an embedded ActiveX control.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Trend Micro OfficeScan Corporate Edition 7.3
No auth needed
Prerequisites: Victim must visit a malicious web page or open a malicious HTML file · ActiveX controls must be enabled in the victim's browser
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/33040
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/784369
Vendor Advisory vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1017664
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24193
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22585
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0638

Scores

EPSS 0.3401
EPSS Percentile 98.2%

Details

CWE
CWE-119
Status published
Products (3)
trend_micro/client-server-messaging_security 3.0
trend_micro/officescan_corporate_edition 7.0
trend_micro/officescan_corporate_edition 7.3
Published Feb 20, 2007
Tracked Since Feb 18, 2026