HP eSupportDiagnostics 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities
BID:26967
Info
HP eSupportDiagnostics 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 26967 |
| Class: | Design Error |
| CVE: |
CVE-2007-6513 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Elazar Broad <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
HP eSupportDiagnostics 1.0.11 .0 |
| Not Vulnerable: | |
Discussion
HP eSupportDiagnostics 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities
The HP eSupportDiagnostics ActiveX control is prone to multiple information-disclosure vulnerabilities.
An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious HTML page.
Successfully exploiting these issues allows remote attackers to obtain the contents of arbitrary files and registry values. Information harvested may aid in further attacks.
These issues affect 'hpediag.dll' 1.0.11.0; other versions may also be affected.
The HP eSupportDiagnostics ActiveX control is prone to multiple information-disclosure vulnerabilities.
An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious HTML page.
Successfully exploiting these issues allows remote attackers to obtain the contents of arbitrary files and registry values. Information harvested may aid in further attacks.
These issues affect 'hpediag.dll' 1.0.11.0; other versions may also be affected.
Exploit / POC
HP eSupportDiagnostics 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities
Attackers can exploit these issues with a browser.
The following exploit example is available:
Attackers can exploit these issues with a browser.
The following exploit example is available:
Solution / Fix
HP eSupportDiagnostics 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
HP eSupportDiagnostics 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities
References:
References:
- [Full-disclosure] HP eSupportDiagnostics hpediags.dll Information Disclosure (Elazar Broad)
- Micro News Homepage (phptoys)
- Microsoft Knowledge Base Article 240797 (Microsoft)