Back to Database
Status published
Critical
CVE-2008-3156
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00...
Vulnerability Description
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-3156
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vupen.com/english/advisories/2008/2008/references
- http://www.securityfocus.com/bid/30086
- https://www.exploit-db.com/exploits/6004
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063061.html
- http://secunia.com/advisories/30841
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063068.html
- http://www.securitytracker.com/id?1020432
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43587
- http://karol.wiesek.pl/files/panda.tgz
More from panda
View All →CVE-2009-3735
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in...
Critical
9.3
CVE-2008-3155
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda...
Critical
9.3
CVE-2008-1471
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+...
High
7.2
CVE-2007-4191
Panda Antivirus 2008 stores service executables under the product's installation...
Medium
6.9
CVE-2007-3969
Buffer overflow in Panda Antivirus before 20070720 allows remote attackers...
Critical
9.3
Affected Vendor
panda
View all reports →Affected Software
panda activescan
Vulnerable Versions:
2.0
Timeline
Official Publish:
July 11th, 2008
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.