CVE-2007-4740

Telecom Italy Alice Messenger - Unauthenticated Registry Manipulation via HPRevolutionRegistryManager ActiveX Control

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4740. PoCs published by rgod.

AI-analyzed exploit summary This exploit leverages an unsafe ActiveX control (HP.Revolution.RegistryManager.dll) to manipulate arbitrary registry keys remotely. It adds a malicious entry to the Run key to execute commands for user creation, privilege escalation, and service manipulation.

Description

The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to create registry keys and values via the arguments to the WriteRegistry method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · htmlremotewindows
https://www.exploit-db.com/exploits/4357

This exploit leverages an unsafe ActiveX control (HP.Revolution.RegistryManager.dll) to manipulate arbitrary registry keys remotely. It adds a malicious entry to the Run key to execute commands for user creation, privilege escalation, and service manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Telecom Italy Alice Messenger (HP.Revolution.RegistryManager.dll v.1)
No auth needed
Prerequisites: Victim must visit a malicious webpage or open the HTML file · Target system must have the vulnerable DLL registered
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Various Sources x_refsource_misc
http://retrogod.altervista.org/telecom_regkey.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/36408
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018644
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38923
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/478449/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25516
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3098

Scores

EPSS 0.0372
EPSS Percentile 88.3%

Details

CWE
CWE-264
Status published
Products (1)
telecom_italy/alice_messenger 1.1
Published Sep 06, 2007
Tracked Since Feb 18, 2026