HP Quick Launch Button 'HPInfoDLL.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1019086 |
|
SecurityTracker URL: http://securitytracker.com/id/1019086
|
|
CVE Reference:
CVE-2007-6331, CVE-2007-6332, CVE-2007-6333
(Links to External Site)
|
Updated: Feb 25 2008
|
Original Entry Date: Dec 12 2007
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 6.3 and prior versions
|
Description:
A vulnerability was reported in HP Quick Launch Button (HP Info Center). A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create specially crafted HTML that, when loaded by the target user, will invoke the 'HPInfoDLL.dll' ActiveX control and execute arbitrary code on the target system. The code will run with the privileges of the target user.
The CLSID of the vulnerable control is:
62DDEB79-15B2-41E3-8834-D3B80493887A
porkythepig reported this vulnerability.
A demonstration exploit is available at:
http://www.milw0rm.com/exploits/4720
The original advisory is available at:
http://www.anspi.pl/~porkythepig/hp-issue/kilokieubasy.txt
|
Impact:
A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
HP has issued the following patches.
For HP Compaq nc, nx, nw and tc Series business notebook PC models (for example, nc6230, nw8440) not running Microsoft .NET 2.0 or later HP 500, 510, 520 and 530 business notebook PC models:
Install HP SoftPaq SP38266 or subsequent
For HP Compaq business notebook PC model numbers ending in the letter b, p, s or w (for example, 6515b, 6910p, 8510w) HP Compaq nc, nx, nw and tc Series business notebook PC models (for example, nc6230, nw8440) running Microsoft .NET 2.0 or later HP, HP Pavilion, and Compaq Presario consumer notebook PCs:
Install HP SoftPaq SP38171 or subsequent
The patches are available by searching at:
http://www.hp,com/
The HP advisory is available at:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486
|
Vendor URL: h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 12 Dec 2007 00:02:23 -0500
Subject: HP Info Center
|
http://www.milw0rm.com/exploits/4720
|
|