CVE-2008-0437
HP Virtual Rooms - Buffer Overflow via ActiveX Control Property Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0437. PoCs published by Elazar.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in HP Virtual Rooms WebHPVCInstall Control (CVE-2008-0437). It uses a heap spray technique to achieve remote code execution by overflowing the `AuthenticationURL` property with a large buffer followed by shellcode.
Description
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit targets a buffer overflow vulnerability in HP Virtual Rooms WebHPVCInstall Control (CVE-2008-0437). It uses a heap spray technique to achieve remote code execution by overflowing the `AuthenticationURL` property with a large buffer followed by shellcode.