SSRT071502Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486 CVE-2007-6332
HP Compaq Notebooks - ActiveX Remote Code Execution
Record summary
CVE-2007-6332 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create or modify arbitrary registry values via the arguments to the SetRegValue method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHP Compaq Notebooks - ActiveX Remote Code ExecutionExploitDB exploitby porkythepigNot analyzed1 file
References
1028055Third-party advisory
http://secunia.com/advisories/28055 1019086vdb entry
http://securitytracker.com/id?1019086 anspi.pl
http://www.anspi.pl/~porkythepig/hp-issue/kilokieubasy.txt 20071211 HP notebooks remote code execution vulnerability (multiple series)mailing list
http://www.securityfocus.com/archive/1/484880/100/100/threaded 26823vdb entry
http://www.securityfocus.com/bid/26823 ADV-2007-4192vdb entry
http://www.vupen.com/english/advisories/2007/4192 hpinfo-hpinfo-information-disclosure(38994)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38994 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6332 4720exploit
https://www.exploit-db.com/exploits/4720