HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Download Vulnerability
BID:29530
Info
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Download Vulnerability
| Bugtraq ID: | 29530 |
| Class: | Design Error |
| CVE: |
CVE-2007-5608 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2008 12:00AM |
| Updated: | Aug 25 2008 03:55PM |
| Credit: | Dennis Rand |
| Vulnerable: |
HP Instant Support 1.0 .22 |
| Not Vulnerable: |
HP Instant Support 1.0.0.24 |
Discussion
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Download Vulnerability
HP Instant Support ActiveX control in 'HPISDataManager.dll' is prone to a vulnerability that lets attackers download arbitrary files.
Attackers may exploit this issue by enticing victims into visiting a maliciously crafted webpage.
Successful exploits will allow remote attackers to download files from arbitrary locations to the affected computer. The attacker can also specify arbitrary download locations on the target system.
NOTE: This issue was previously covered in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities), but has been given its own record because of new information.
HP Instant Support ActiveX control in 'HPISDataManager.dll' is prone to a vulnerability that lets attackers download arbitrary files.
Attackers may exploit this issue by enticing victims into visiting a maliciously crafted webpage.
Successful exploits will allow remote attackers to download files from arbitrary locations to the affected computer. The attacker can also specify arbitrary download locations on the target system.
NOTE: This issue was previously covered in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities), but has been given its own record because of new information.
Exploit / POC
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Download Vulnerability
Attackers may exploit this issue by enticing victims into opening a maliciously crafted webpage.
The following exploit code is available:
Attackers may exploit this issue by enticing victims into opening a maliciously crafted webpage.
The following exploit code is available:
Solution / Fix
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Download Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Download Vulnerability
References:
References:
- HP Instant Support Home Page (HP )
- HP Instant Support Security Bulletin (HP )
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Advisory (953839) Cumulative Security Update of ActiveX Kill (Microsoft)
- VU#949587 HP Online Support Service ActiveX DownloadFile() arbitrary file downlo (US-CERT)