CVE-2008-1472
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 39%
from disclosure to weapon813 days
Published on NVDMar 24
1st PoC+813d
metasploitMar 16
VulnCheck+768d
exploitation probability
39%top 2% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16577unverifiedcve_referencewww.exploit-db.com/exploits/5264unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://community.ca.com/blogs/casecurityresponseblog/archive/2008/3/28.aspxhttp://secunia.com/advisories/29408https://exchange.xforce.ibmcloud.com/vulnerabilities/41225https://www.exploit-db.com/exploits/5264http://www.securityfocus.com/archive/1/489893/100/0/threadedhttp://www.securityfocus.com/archive/1/490263/100/0/threadedhttp://www.securityfocus.com/bid/28268http://www.securitytracker.com/id?1019617http://www.vupen.com/english/advisories/2008/0902/references