CVE-2010-3007

HP Data Protector <4.0 - Privilege Escalation/DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2010-3007. PoCs published by Metasploit, AbdulAziz Hariri, juan vazquez, including Metasploit module exploits/windows/misc/hp_dataprotector_dtbclslogin.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in HP Data Protector 4.0 SP1 during the login process, leveraging an insecure use of Utf8Cpy in the DtbClsLogin function. It achieves remote code execution with SYSTEM privileges by sending a maliciously crafted authentication request.

Description

Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 allows local users to gain privileges or cause a denial of service via unknown vectors.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/23290

This Metasploit module exploits a stack buffer overflow in HP Data Protector 4.0 SP1 during the login process, leveraging an insecure use of Utf8Cpy in the DtbClsLogin function. It achieves remote code execution with SYSTEM privileges by sending a maliciously crafted authentication request.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector Express 4.0 SP1 (build 43064)
No auth needed
Prerequisites: Network access to the target service on port 3817 · Target system running HP Data Protector Express 4.0 SP1
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by AbdulAziz Hariri, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/hp_dataprotector_dtbclslogin.rb

This Metasploit module exploits a stack buffer overflow in HP Data Protector 4.0 SP1 during the login process via the DtbClsLogin function. It leverages an insecure use of Utf8Cpy (strcpy-like function) with the username to achieve remote code execution with SYSTEM privileges.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector Express 4.0 SP1 (build 43064)
No auth needed
Prerequisites: Network access to the target system on port 3817 · HP Data Protector Express 4.0 SP1 running on the target
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Various Sources vendor-advisory x_refsource_hp
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02498535

Scores

EPSS 0.0506
EPSS Percentile 91.2%

Details

Status published
Products (3)
hp/data_protector_express 3.1 (2 CPE variants)
hp/data_protector_express 3.5 sp1 (4 CPE variants)
hp/data_protector_express 4.0 (4 CPE variants)
Published Sep 09, 2010
Tracked Since Feb 18, 2026