HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Delete Vulnerability
BID:29536
Info
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Delete Vulnerability
| Bugtraq ID: | 29536 |
| Class: | Design Error |
| CVE: |
CVE-2007-5610 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2008 12:00AM |
| Updated: | Aug 25 2008 03:35PM |
| Credit: | Dennis Rand |
| Vulnerable: |
HP Instant Support 1.0 .22 |
| Not Vulnerable: |
HP Instant Support 1.0.0.24 |
Discussion
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Delete Vulnerability
HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to a vulnerability that lets attackers delete arbitrary files on the affected computer in the context of the application using the ActiveX control. Successful attacks can result in denial-of-service conditions.
HP Instant Support 1.0.0.22 and earlier versions are affected.
NOTE: This issue was previously covered in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities), but has been given its own record because of new information.
HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to a vulnerability that lets attackers delete arbitrary files on the affected computer in the context of the application using the ActiveX control. Successful attacks can result in denial-of-service conditions.
HP Instant Support 1.0.0.22 and earlier versions are affected.
NOTE: This issue was previously covered in BID 29526 (HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified Code Execution Vulnerabilities), but has been given its own record because of new information.
Exploit / POC
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Delete Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious web page.
The following proof of concept is available:
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious web page.
The following proof of concept is available:
Solution / Fix
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Delete Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
HP Instant Support 'HPISDataManager.dll' ActiveX Control Arbitrary File Delete Vulnerability
References:
References:
- HP Instant Support Home Page (HP )
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Advisory (953839) Cumulative Security Update of ActiveX Kill (Microsoft)
- Advisory - HP Online Support Service ActiveX multiple vulnerabilities (CSIS Security Research and Intelligence)
- VU#857539 HP Online Support Service ActiveX DeleteSingleFile() arbitrary file de (US-CERT)