HP Software Update HPeDiag ActiveX Control Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in HP Software Update, which could be exploited by remote attackers to gain knowledge of sensitive information or take complete control of an affected system.
1. Due to a buffer overflow error in the HPeDiag ActiveX control when handling malformed data passed to the "GetXmlFromIni()" method, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
2. Due to a design error in various controls that do not restrict access to certain methods, which could be exploited by attackers to e.g. gain unauthorized read access to arbitrary files and registery keys via a specially crafted web page.
Impact
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- HP Software Update version 4.000.009.002 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to HP Software Update version 4.000.010.008.
Vulnerability Identifier
Source
Related Link
Share with