CVE-2013-4800

HP LoadRunner < 11.52 - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-4800. PoCs published by Metasploit, Unknown, juan vazquez, including Metasploit module exploits/windows/misc/hp_loadrunner_magentproc.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in HP LoadRunner's magentproc.exe via a crafted TCP request to port 443, allowing arbitrary code execution. It uses SEH overwrites and a prepended stack adjustment for reliable exploitation.

Description

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1735.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/28809

This Metasploit module exploits a stack buffer overflow in HP LoadRunner's magentproc.exe via a crafted TCP request to port 443, allowing arbitrary code execution. It uses SEH overwrites and a prepended stack adjustment for reliable exploitation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP LoadRunner before 11.52
No auth needed
Prerequisites: Network access to TCP port 443 on the target · Vulnerable version of HP LoadRunner installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Unknown, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/hp_loadrunner_magentproc.rb

This Metasploit module exploits a stack buffer overflow in HP LoadRunner's magentproc.exe (CVE-2013-4800) by sending a crafted packet to trigger arbitrary code execution. It uses SEH overwrites and a prepended stack adjustment for reliable exploitation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP LoadRunner before 11.52
No auth needed
Prerequisites: Network access to the target's magentproc.exe service on port 443
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/123533
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/85960
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/95644
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/61446
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-13-169

Scores

EPSS 0.7137
EPSS Percentile 98.7%

Details

Status published
Products (7)
hp/loadrunner 9.0.0
hp/loadrunner 9.50.0
hp/loadrunner 9.51
hp/loadrunner 9.52
hp/loadrunner 11.0.0.0
hp/loadrunner 11.50
hp/loadrunner < 11.51
Published Jul 29, 2013
Tracked Since Feb 18, 2026