vendor:
HP All-in-One Series Web Release, HP Photo & Imaging Gallery version 1.1
by:
Brian Mariani, Jonathan Sarba
7.5
CVSS
HIGH
Heap Overflow
122
CWE
Product Name: HP All-in-One Series Web Release, HP Photo & Imaging Gallery version 1.1
Affected Version From: 2.0.0.138
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: hpqutil.dll
Platforms Tested: Windows XP
2007
ActiveX hpqutil!ListFiles hpqutil.dll – Remote heap overflow
The hpqutil.dll in HP All-in-One Series Web Release and HP Photo & Imaging Gallery version 1.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap overflow) via a crafted web page with an ActiveX control that triggers a heap overflow, as demonstrated by a call to the FindFile function.
Mitigation:
Unregistering hpqutil.dll using regsvr32, Activate the Kill bit zero in clsid F3F381A3-4795-41FF-8190-7AA2A8102F85