HP Data Protector Cell Manager 'crs.exe' Multiple Opcodes Remote Code Execution Vulnerability
Severity: CRITICAL
Advisory Date: JUL 21, 2015
DESCRIPTION
Multiple stack buffer overflows exist in HP Data Protector. The vulnerabilities are due to a lack of input sanitization on Strings provided with various opcodes. A remote unauthenticated attacker could exploit these vulnerabilities by sending a crafted request to the vulnerable service. Successful exploitation could cause a stack buffer overflow resulting in code execution in the context of the the affected service.
TREND MICRO PROTECTION INFORMATION
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1006133