CVE-2008-2434

critical

Description

The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary library file onto a client system via a "custom update server" argument. NOTE: this can be leveraged for code execution by writing to a Startup folder.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/47524

http://www.vupen.com/english/advisories/2008/3464

http://www.securityfocus.com/bid/32965

http://www.securityfocus.com/archive/1/499495/100/0/threaded

http://www.kb.cert.org/vuls/id/541025

http://securityreason.com/securityalert/4802

http://secunia.com/secunia_research/2008-32/

http://secunia.com/advisories/31337

http://osvdb.org/50941

http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1038646&id=EN-1038646

Details

Source: Mitre, NVD

Published: 2008-12-23

Updated: 2026-04-23

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.06998