vendor:
HP Photo Digital Imaging
by:
callAX
7.5
CVSS
HIGH
Arbitrary Data Write
Other
CWE
Product Name: HP Photo Digital Imaging
Affected Version From: 2.0.0.133
Affected Version To: 2.0.0.133
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 with IE 6.0 / 7.0, Windows vista Professional with IE 7.0
2007
hpqxml.dll 2.0.0.133 from HP Digital Imaging Arbitary Data Write
The saveXMLAsFile method in hpqxml.dll allows malicious users to write arbitrary data to any file on a vulnerable system. The method does not check if it is being called from the application or from a malicious user, and it does not check the file headers before writing.
Mitigation:
1. Activate the Kill bit zero in clsid:9C0A0321-B328-466C-8ECA-B9A5522466D3. 2. Unregister hpqxml.dll using regsvr32.