CVE-2011-2404

HP Easy Printer Care Software < 2.5 - Code Injection

Title source: rule

Description

A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-4786 and CVE-2011-4787.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/17697
metasploit WORKING POC GREAT
by Andrea Micalizzi, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/hp_easy_printer_care_xmlsimpleaccessor.rb

Scores

EPSS 0.8008
EPSS Percentile 99.1%

Details

CWE
CWE-94
Status published
Products (1)
hp/easy_printer_care_software < 2.5
Published Aug 11, 2011
Tracked Since Feb 18, 2026