CVE-2014-7892
HP OLE Point of Sale Driver < 1.13.001 - Remote Code Execution via OPOSMSR.ocx
Title source: manualDescription
The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSMSR.ocx for Mini MSR magnetic stripe readers, Retail Integrated Dual-Head MSR magnetic stripe readers, Integrated Single Head MSR w/o SRED magnetic stripe readers, Integrated Single Head w/o MSR SRED magnetic stripe readers, RP7 Single Head MSR w/o SRED magnetic stripe readers, POS keyboards, and POS keyboards with MSR, aka ZDI-CAN-2508.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031840
Vendor Advisory vendor-advisory
x_refsource_hp
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04583185
Scores
EPSS
0.2881
EPSS Percentile
96.6%
Details
Status
published
Products (1)
hp/ole_point_of_sale_driver
< 1.13.001
Published
Mar 09, 2015
Tracked Since
Feb 18, 2026