vendor:
NNM
by:
muts & sinn3r
7.5
CVSS
HIGH
Remote Buffer Overflow
CWE
Product Name: NNM
Affected Version From:
Affected Version To:
Patch Exists: No
Related CWE:
CPE:
Platforms Tested: Windows XP
Unknown
HP NNP ovalarm.exe CGI Remote Buffer Overflow – Pre Authentication
This exploit targets the HP NNP ovalarm.exe CGI and allows for a remote buffer overflow. It has been tested on XP SP3 + IIS + NNM Release B.07.50.
Mitigation:
To mitigate this vulnerability, users should install the patch NNM_01187 Uninstall and reboot the system. Additionally, they should set w3svc/CreateProcessAsUser to 'false' using the command 'cscript.exe adsutil.vbs set w3svc/CreateProcessAsUser 'false'' in the command prompt.