SSRT071502Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486 CVE-2007-6333
HP Compaq Notebooks - ActiveX Remote Code Execution
Record summary
CVE-2007-6333 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.
Description
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote attackers to read arbitrary registry values via the arguments to the GetRegValue method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHP Compaq Notebooks - ActiveX Remote Code ExecutionExploitDB exploitby porkythepigNot analyzed1 file
References
1028055Third-party advisory
http://secunia.com/advisories/28055 1019086vdb entry
http://securitytracker.com/id?1019086 anspi.pl
http://www.anspi.pl/~porkythepig/hp-issue/kilokieubasy.txt 20071211 HP notebooks remote code execution vulnerability (multiple series)mailing list
http://www.securityfocus.com/archive/1/484880/100/100/threaded 26823vdb entry
http://www.securityfocus.com/bid/26823 ADV-2007-4192vdb entry
http://www.vupen.com/english/advisories/2007/4192 hpinfo-hpinfo-information-disclosure(38994)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38994 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6333 4720exploit
https://www.exploit-db.com/exploits/4720