CVE-2007-6333

HPInfoDLL.HPInfo.1 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-6333. PoCs published by porkythepig.

AI-analyzed exploit summary This is a detailed technical analysis of CVE-2007-6331, which involves insecure methods in the HP Info Center ActiveX control (HPInfoDLL.dll) allowing remote code execution and registry manipulation. The writeup explains the vulnerable methods (GetRegValue, SetRegValue, LaunchApp) and attack vectors, including silent remote execution via windowless processes.

Description

The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote attackers to read arbitrary registry values via the arguments to the GetRegValue method.

Exploits (1)

exploitdb WRITEUP VERIFIED
by porkythepig · htmlremotewindows
https://www.exploit-db.com/exploits/4720

This is a detailed technical analysis of CVE-2007-6331, which involves insecure methods in the HP Info Center ActiveX control (HPInfoDLL.dll) allowing remote code execution and registry manipulation. The writeup explains the vulnerable methods (GetRegValue, SetRegValue, LaunchApp) and attack vectors, including silent remote execution via windowless processes.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Info Center v1.0.1.1, HPInfoDll.dll ActiveX CTL v1.0
No auth needed
Prerequisites: Victim must visit a malicious website using Internet Explorer · HP Info Center software must be installed on the target system
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26823
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4720
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/4192
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1019086
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38994
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28055
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/484880/100/100/threaded

Scores

EPSS 0.0868
EPSS Percentile 94.4%

Details

Status published
Products (2)
hp/info_center 1.0.1.1
hp/quick_launch_button < 6.3
Published Dec 13, 2007
Tracked Since Feb 18, 2026