Skip to main content

HP Software Update HPeDiag ActiveX Control Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 28 Apr 2008 5351 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in HP Software Update, which could be exploited by remote attackers to gain knowledge of sensitive information or take complete control of an affected system.

1. Due to a buffer overflow error in the HPeDiag ActiveX control when handling malformed data passed to the "GetXmlFromIni()" method, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.

2. Due to a design error in various controls that do not restrict access to certain methods, which could be exploited by attackers to e.g. gain unauthorized read access to arbitrary files and registery keys via a specially crafted web page.


Impact

  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • HP Software Update version 4.000.009.002 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to HP Software Update version 4.000.010.008.


Vulnerability Identifier


Source


Related Link