9.3
CVSSv2

CVE-2007-6506

Published: 20/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and previous versions, including 3.0.8.4, allows remote malicious users to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

Vulnerable Product Search on Vulmon Subscribe to Product

hp software update

hp software update 3.0.8.4

Exploits

Advisory: ///////// There is another remotely exploitable flaw within software preinstalled in HP notebook machines This time, the culprit is automatic software update tool provided by the vendorThe Potential exploitation may lead to user files loss or altering vital system files (eg kernel), thus leaving PC unbootable Overview: ////// ...