Threat Monitor
« Back to list
Troj.Exploit.HTML.VML.e
| Aliases: | |
|---|
| Pattern: | 200904271330 |
|---|
| Threat Type | Propagation Methods | Systems Affected | Risk Level |
| | | - Windows NT
- Windows XP
- Windows 2000
- Windows 95/98/ME
- MS-DOS
- Other
| |
This malicious program exploits vulnerability CVE-2007-6016 and CVE-2007-6017.
Symantec Backup Exec is prone to multiple vulnerabilities that allow attackers to overwrite arbitrary files.
Two boundary errors within the PVATLCalendar.PVCalendar.1 (pvcalendar.ocx) ActiveX control when handling strings assigned to various properties can be exploited to cause stack-based buffer overflows by assigning overly-long strings to the affected properties and then calling the "Save()" method .
Successfully exploiting these issues will allow the attacker to corrupt and overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control.
Affected Versions:
Symantec Backup Exec for Windows Servers 12.0
Symantec Backup Exec for Windows Servers 11d
Back to Top