Executive Summary

Summary
Title HP Software Update Running on Windows, Remote Execution of Arbitrary Code, Gain Privileged Access
Informations
Name HPSBGN02301 SSRT071508 First vendor Publication 2007-12-21
Vendor HP Last vendor Modification 2008-01-02
Severity (Vendor) N/A Revision 2

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A potential security vulnerability has been identified with HP Software Update running on Windows. The vulnerability could be exploited remotely to execute arbitrary code or gain privileged access.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01311918

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2

Open Source Vulnerability Database (OSVDB)

Id Description
40238 HP Software Update HPRulesEngine.ContentCollection ActiveX (RulesEngine.dll) ...

40237 HP Software Update HPRulesEngine.ContentCollection ActiveX (RulesEngine.dll) ...

Snort® IPS/IDS

Date Description
2014-01-10 HP Software Update RulesEngine.dll ActiveX function call unicode access
RuleID : 14898 - Revision : 6 - Type : WEB-ACTIVEX
2014-01-10 HP Software Update RulesEngine.dll ActiveX function call access
RuleID : 14897 - Revision : 10 - Type : BROWSER-PLUGINS
2014-01-10 HP Software Update RulesEngine.dll ActiveX clsid unicode access
RuleID : 13220 - Revision : 9 - Type : WEB-ACTIVEX
2014-01-10 HP Software Update RulesEngine.dll ActiveX clsid access
RuleID : 13219 - Revision : 17 - Type : BROWSER-PLUGINS

Nessus® Vulnerability Scanner

Date Description
2007-12-23 Name : The remote Windows host has an ActiveX control that allows reading and writin...
File : hp_update_rulesengine_activex_insecure.nasl - Type : ACT_GATHER_INFO