Tuesday, December 11, 2007

HP Compaq Notebooks ActiveX Remote Code Execution Exploit

Multiple Hewlett-Packard notebook series are prone to a remote code execution attack.

The manufacturer's preinstalled software contains a critical flaw within the software built to support one-touch button quick feature access.

Overview:
/////////

Software called "HP Info Center" is shipped with almost every HP laptop model for few years. It is designed to support user with quick system information and hardware configuration using single button touch.

One of its ActiveX controls deployed by default by the vendor has three insecure methods that allow a malicious person to target the HP notebook machines for a remote code execution and remote registry manipulation based attacks.

Impact:
///////

Remote code execution
Remote system registry read/write access
Remote shell command execution

Credits:
////////

Issue discovery and research: porkythepig
Contact: porkythepig@anspi.pl

--------------------

Exploit and Details = http://www.milw0rm.com/exploits/4720

No comments:

Post a Comment