7.6
CVSSv2

CVE-2007-3554

Published: 04/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 770
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check prior to 1.5.0.3 allows remote malicious users to execute arbitrary code via a long argument to the queryHub function.

Vulnerable Product Search on Vulmon Subscribe to Product

hp instant support

Exploits

---------------------------------------------------------------------------------- HP Instant Support - Driver Check Remote Buffer Overflow Exploit author: Carlo Di Dato (aka shinnai) mail: shinnai[at]autistici[dot]org site: shinnaialtervistaorg Tested on Windows XP Professional SP2 full patched with IE7 Special thanks to: rgod fo ...
source: wwwsecurityfocuscom/bid/24730/info HP Instant Support ActiveX control is prone to a remote buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized memory buffer Exploiting this issue allows remote attackers to execute arbitrary code in the context ...