CVE-2011-4789

HP Diagnostics - Memory Corruption

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2011-4789. PoCs published by Metasploit, AbdulAziz Hariri, hal, including Metasploit module exploits/windows/misc/hp_magentservice.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in HP Diagnostics Server's magentservice.exe via a crafted packet sent to port 23472. It leverages SEH overwrite for arbitrary code execution, targeting version 9.10 with a specific return address.

Description

Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attackers to execute arbitrary code via a crafted size value in a packet. NOTE: it was originally reported that the affected product is HP Diagnostics Server, but HP states that "the vulnerable product is actually HP LoadRunner."

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18423

This Metasploit module exploits a stack buffer overflow in HP Diagnostics Server's magentservice.exe via a crafted packet sent to port 23472. It leverages SEH overwrite for arbitrary code execution, targeting version 9.10 with a specific return address.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Diagnostics Server 9.10
No auth needed
Prerequisites: Network access to target port 23472 · SSL3 support
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by AbdulAziz Hariri, hal · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/hp_magentservice.rb

This Metasploit module exploits a stack buffer overflow in HP Diagnostics Server's magentservice.exe by sending a crafted packet to TCP port 23472. It leverages SEH overwrite techniques to achieve remote code execution on vulnerable systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Diagnostics Server 9.10
No auth needed
Prerequisites: Network access to TCP port 23472 · Vulnerable version of HP Diagnostics Server
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/78309
Third Party Advisory x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-12-016/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51398

Scores

EPSS 0.6480
EPSS Percentile 99.1%

Details

CWE
CWE-119
Status published
Products (1)
hp/diagnostics
Published Jan 13, 2012
Tracked Since Feb 18, 2026