Code Execution Vulnerability in HP Instant Support by HP
CVE-2008-0953

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
4 June 2008

Summary

The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll, found in HP Instant Support versions prior to 1.0.0.24, allows remote attackers to execute arbitrary programs. This can be achieved by supplying a malicious .exe filename as an argument to the function, enabling potential exploitation of the vulnerability by unauthorized users.

References

EPSS Score

14% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.