Code Execution Vulnerability in HP Instant Support by HP
CVE-2008-0953
Currently unrated
Summary
The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll, found in HP Instant Support versions prior to 1.0.0.24, allows remote attackers to execute arbitrary programs. This can be achieved by supplying a malicious .exe filename as an argument to the function, enabling potential exploitation of the vulnerability by unauthorized users.
References
EPSS Score
14% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved