Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Trend Micro HouseCall "notifyOnLoadNative()" Vulnerability

Subscribe

Check Point Reference: CPAI-2009-025
Date Published:
Severity:
Source: Secunia Research
Industry Reference(s): CVE-2008-2434
CVE-2008-2435
Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Trend Micro HouseCall ActiveX Control 6.51.0.1028 and 6.6.0.1278
Vulnerability Description
A vulnerability was reported in Trend Micro HouseCall . HouseCall is an application for checking whether your computer has been infected by viruses, spyware, or other malware. The vulnerability is caused by a use-after-free error in the HouseCall ActiveX control.  This can be exploited to dereference previously freed memory by tricking the user into opening a web page containing a specially crafted function. Successful exploitation may allow remote code execution.
Vulnerability Details
The Trend Micro HouseCall ActiveX control (Housecall_ActiveX.dll) contains a use-after-free vulnerability.  Using a web page containing a specially crafted call to notifyOnLoadNative(), an attacker can write to heap memory and potentially execute arbitrary code.

Protection Overview
By enabling this protection, IPS-1 will detect and block attempts to access the ActiveX controls for Trend Micro HouseCall.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > Badfiles, and select the ActiveX Parser protection group.
3. Click User defined bad ActiveX Class ID (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: Badfiles ActiveX class in HTML file Alert/Filter
Description: User defined bad ActiveX Class ID