HP Intelligent Management Center UAM Buffer Overflow Vulnerability

  Severity: CRITICAL
  Advisory Date: JUL 21, 2015

  DESCRIPTION

A vulnerability has been reported in HP Intelligent Management Center UAM, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a boundary error in the uam.exe component when logging certain actions. This can be exploited to cause a stack-based buffer overflow via a specially crafted datagram sent to UDP port 1811.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1005234
  Trend Micro Deep Security DPI Rule Name: 1005234 - HP Intelligent Management Center UAM Buffer Overflow Vulnerability

  AFFECTED SOFTWARE AND VERSION

  • HP Intelligent Management Center