HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Creation Vulnerability
BID:29535
Info
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Creation Vulnerability
| Bugtraq ID: | 29535 |
| Class: | Design Error |
| CVE: |
CVE-2008-0952 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2008 12:00AM |
| Updated: | Aug 25 2008 07:25PM |
| Credit: | Dennis Rand |
| Vulnerable: |
HP Instant Support 1.0 .22 |
| Not Vulnerable: |
HP Instant Support 1.0.0.24 |
Discussion
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Creation Vulnerability
HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to a vulnerability that lets attackers create and overwrite files with arbitrary, attacker-controlled content.
Successful exploits may compromise affected computers and aid in further attacks.
HP Instant Support 1.0.0.22 and earlier versions are affected.
NOTE: This issue was previously covered in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities), but has been given its own record because of new information.
HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to a vulnerability that lets attackers create and overwrite files with arbitrary, attacker-controlled content.
Successful exploits may compromise affected computers and aid in further attacks.
HP Instant Support 1.0.0.22 and earlier versions are affected.
NOTE: This issue was previously covered in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities), but has been given its own record because of new information.
Exploit / POC
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Creation Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious web page.
The following proof of concept is available:
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious web page.
The following proof of concept is available:
Solution / Fix
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Creation Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Creation Vulnerability
References:
References:
- HP Instant Support Home Page (HP )
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Advisory (953839) Cumulative Security Update of ActiveX Kill (Microsoft)
- Advisory - HP Online Support Service ActiveX multiple vulnerabilities (CSIS Security Research and Intelligence)
- VU#190939 Vulnerability Note VU#190939 HP Online Support Service ActiveX Ap (US-CERT)