CVE-2011-0922

HP Data Protector - Remote Code Execution via EXEC_SETUP Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2011-0922. PoCs published by Ben Turner, fdiskyou, including Metasploit module exploits/windows/misc/hp_dataprotector_install_service.

AI-analyzed exploit summary This Metasploit module exploits a remote code execution vulnerability in HP Data Protector's omniinet process by leveraging an SMB share to drop and execute a malicious payload. It targets versions 6.10, 6.11, and 6.20 on Windows systems.

Description

The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Ben Turner · rubyremotewindows
https://www.exploit-db.com/exploits/27271

This Metasploit module exploits a remote code execution vulnerability in HP Data Protector's omniinet process by leveraging an SMB share to drop and execute a malicious payload. It targets versions 6.10, 6.11, and 6.20 on Windows systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 6.10, 6.11, 6.20
No auth needed
Prerequisites: SMB share named 'Omniback' with subfolder 'i386' accessible to the target · Network access to the target's SMB and omniinet services
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Ben Turner · pythonremotewindows
https://www.exploit-db.com/exploits/19288

This exploit targets CVE-2011-0922 in HP Data Protector Client (versions 6.11 & 6.20) by sending a crafted payload to execute a remote command. It leverages a share path to execute 'installservice.exe' with SYSTEM privileges.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector Client 6.11 & 6.20
No auth needed
Prerequisites: Accessible SMB share with 'installservice.exe' · Network access to target port · SYSTEM account access to the share
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by fdiskyou · pythonremotewindows
https://www.exploit-db.com/exploits/17345

This PoC exploits CVE-2011-0922 in HP Data Protector by crafting a malicious packet to trigger remote code execution via the EXEC_SETUP command. It instructs the target to download and execute a payload from a specified share or HTTP location.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector Client 6.11
No auth needed
Prerequisites: Network access to target on port 5555 · Ability to host malicious payload on share/HTTP
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Ben Turner · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/hp_dataprotector_install_service.rb

This Metasploit module exploits a vulnerability in HP Data Protector's OmniInet service to achieve remote code execution by creating a custom payload executable. It leverages the install service function to execute arbitrary code on the target system.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 6.10/6.11/6.20
No auth needed
Prerequisites: SMB server with a share named 'Omniback' containing an 'i386' subfolder · Network access to the target's OmniInet service on port 5555
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=130391284726795&w=2
Third Party Advisory x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-11-056/
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0308
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46234
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/516272/100/0/threaded

Scores

EPSS 0.6422
EPSS Percentile 99.1%

Details

CWE
CWE-20
Status published
Products (1)
hp/data_protector
Published Feb 09, 2011
Tracked Since Feb 18, 2026