HP Software Update 'RulesEngine.dll' ActiveX Control Multiple File Overwrite Vulnerabilities
BID:26950
Info
HP Software Update 'RulesEngine.dll' ActiveX Control Multiple File Overwrite Vulnerabilities
| Bugtraq ID: | 26950 |
| Class: | Design Error |
| CVE: |
CVE-2007-6506 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2007 12:00AM |
| Updated: | Jan 04 2008 05:50PM |
| Credit: | porkythepig <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
HP Software Update 3.0.8.4 |
| Not Vulnerable: | |
Discussion
HP Software Update 'RulesEngine.dll' ActiveX Control Multiple File Overwrite Vulnerabilities
HP Software Update 'RulesEngine.dll' ActiveX control is prone to multiple vulnerabilities that attackers can exploit to overwrite arbitrary user files and SYSTEM files. The issues stem from insecure methods used within 'RulesEngine.dll'.
An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious HTML page.
Successfully exploiting these issues allows remote attackers to overwrite arbitrary user files as well as critical SYSTEM files, which can prevent the computer from restarting.
HP Software Update 3.0.8.4 with 'RulesEngine.dll' ActiveX control 1.0 is vulnerable; other versions may also be affected.
Note that multiple HP laptop models ship with this software.
HP Software Update 'RulesEngine.dll' ActiveX control is prone to multiple vulnerabilities that attackers can exploit to overwrite arbitrary user files and SYSTEM files. The issues stem from insecure methods used within 'RulesEngine.dll'.
An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious HTML page.
Successfully exploiting these issues allows remote attackers to overwrite arbitrary user files as well as critical SYSTEM files, which can prevent the computer from restarting.
HP Software Update 3.0.8.4 with 'RulesEngine.dll' ActiveX control 1.0 is vulnerable; other versions may also be affected.
Note that multiple HP laptop models ship with this software.
Exploit / POC
HP Software Update 'RulesEngine.dll' ActiveX Control Multiple File Overwrite Vulnerabilities
Attackers can exploit these issues with a browser.
The following exploit example is available:
Attackers can exploit these issues with a browser.
The following exploit example is available:
Solution / Fix
HP Software Update 'RulesEngine.dll' ActiveX Control Multiple File Overwrite Vulnerabilities
Solution:
The vendor has released updates to address this issue. Please see the referenced advisory for further information.
Solution:
The vendor has released updates to address this issue. Please see the referenced advisory for further information.
References
HP Software Update 'RulesEngine.dll' ActiveX Control Multiple File Overwrite Vulnerabilities
References:
References: