HP Instant Support ActiveX Control Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in HP Instant Support, which could be exploited by remote attackers to manipulate data or take complete control of an affected system.
1. Due to buffer overflow errors in the "HPISDataManager.dll" ActiveX control when processing malformed data passed to the "ExtractCab()", "GetFileTime()", "MoveFile()" and "RegistryString()" methods, which could be exploited by remote attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a specially crafted web page.
2. Due to a design error in the "HPISDataManager.dll" ActiveX control that includes the insecure methods "AppendStringToFile()", "DownloadFile()", "StartApp()" and "DeleteSingleFile()", which could be exploited by malicious web sites to download, execute or delete arbitrary files.
Impact
- Remote Code Execution
System / Technologies affected
- HP Instant Support version 1.0.0.22 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to HP Instant Support version 1.0.0.24 :
http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
Vulnerability Identifier
- CVE-2007-5604
- CVE-2007-5605
- CVE-2007-5606
- CVE-2007-5607
- CVE-2007-5608
- CVE-2007-5610
- CVE-2008-0952
- CVE-2008-0953
Source
Related Link
Share with