HP HPeDiag ActiveX Control Multiple Information Disclosure and Remote Code Execution Vulnerabilities
BID:28929
Info
HP HPeDiag ActiveX Control Multiple Information Disclosure and Remote Code Execution Vulnerabilities
| Bugtraq ID: | 28929 |
| Class: | Unknown |
| CVE: |
CVE-2008-0712 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2008 12:00AM |
| Updated: | Oct 26 2010 03:28PM |
| Credit: | Chew Keong TAN of vuln.sg |
| Vulnerable: |
HP HPeDiag 4.000.009.002 HP HPeDiag 0 |
| Not Vulnerable: |
HP HPeDiag 4.000.010.008 |
Discussion
HP HPeDiag ActiveX Control Multiple Information Disclosure and Remote Code Execution Vulnerabilities
HPeDiag ActiveX control is prone to multiple information-disclosure and remote code-execution vulnerabilities.
An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious HTML page.
Successfully exploiting these issues would allow an attacker to execute arbitrary code within the context of the application that invokes the ActiveX control (typically Internet Explorer) and to obtain sensitive information.
HPeDiag ActiveX control is prone to multiple information-disclosure and remote code-execution vulnerabilities.
An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious HTML page.
Successfully exploiting these issues would allow an attacker to execute arbitrary code within the context of the application that invokes the ActiveX control (typically Internet Explorer) and to obtain sensitive information.
Exploit / POC
HP HPeDiag ActiveX Control Multiple Information Disclosure and Remote Code Execution Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP HPeDiag ActiveX Control Multiple Information Disclosure and Remote Code Execution Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
HP HPeDiag ActiveX Control Multiple Information Disclosure and Remote Code Execution Vulnerabilities
References:
References:
- HP Homepage (HP)
- Microsoft Knowledge Base Article 240797 (Microsoft)