Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-4786

Опубликовано: 12 янв. 2012
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-2404 and CVE-2011-4787.

Комментарий

http://www.zerodayinitiative.com/advisories/ZDI-12-013/

"The specific flaw exists within the XMLCacheMgr class ActiveX control (CLSID 6F255F99-6961-48DC-B17E-6E1BCCBC0EE3). The CacheDocumentXMLWithId() method is vulnerable to directory traversal and arbitrary write, which allows an attacker to write malicious content to the filesystem. A remote attacker could leverage this vulnerability to gain code execution under the context of the web browser."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hp:easy_printer_care_software:*:*:*:*:*:*:*:*
Версия до 2.5 (включая)

EPSS

Процентиль: 98%
0.63634
Средний

9.3 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
больше 3 лет назад

A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-2404 and CVE-2011-4787.

EPSS

Процентиль: 98%
0.63634
Средний

9.3 Critical

CVSS2

Дефекты

CWE-94