Zero Day Flaw Affects 82 HP Laptop Models
- by Bill Lindner on 20071218 @ 10:36PM EST | google it | send to friends
- Filed under Security | (related terms: hp, laptop, windows xp, vulnerability, code execution)
Hewlett-Packard (HP) has issued an hp.com warning regarding a gaping security hole that affects 82 laptop models running Windows 2000, Windows XP and Windows Vista. According to reports from the company, the 'backdoor' could put users at risk for drive-by code execution attacks. (Source: zdnet.com)
The 82 laptop models are listed in the advisory from HP as open to the ActiveX vulnerability found on the HP Info Center software. A roadmap for exploiting the vulnerability is making rounds on the Internet. HP has rated the issue as "critical."
To run the exploit, all the laptop owner has to to is visit a malicious web site while using Microsoft's Internet Explorer. Risks include remote code execution, remote system registry read/write access and remote shell command execution.
The ActiveX control that is vulnerable is identified as HPInfoDLL.dll, marked as "Safe for Scripting" by default.
At the bottom of the HP warning are instructions for applying the 'patch.' The patch does not immediately fix the vulnerability, but disables the HP Info Center software instead. The 'patch' (sp38166) can be downloaded from hp.com.
Visit Bill's Links and More for more great tips, just like this one!
Related articles:
- 2007/03/02 SupportSoft Tech Support Tools Leave PCs Vulnerable to ...
- 2007/02/15 Major Security Flaw Discovered in the Microsoft Malware ...
- 2008/01/09 The First 500GB Hard Drive Designed For a Laptop
- 2007/03/27 HP's newest Energy Star PCs ship with Windows XP
- 2007/11/13 HP KO'd in Digital Camera Business
- 2007/09/14 HP Invades Mobile Phone Industry
- 2006/11/14 HP Goes Green
- 2008/02/18 Best Buy Slapped With $54 Million Lawsuit for Lost Laptop
- 2008/01/18 Apple Introduces The Thinnest Laptop In The World!
- 2007/11/28 Windows XP SP3 To Deliver Performance Boost
Stay Informed: Subscribe Free to Infopackets, Today! Get your daily fix of Microsoft Windows news, reviews, tech tips, plus free software (freeware) goodies daily -- all absolutely free -- delivered straight to your email inbox! Bonus: join our website today and you'll also receive our highly coveted Top 10 Tech Reports, including: Top 10 PC Security Essentials, Windows Optimization Secrets, Top Freeware Antivirus, MS Office alternatives and more. Don't delay: subscribe today! Click here for more info.
Infopackets Game of the Week
Secrets of the Dark: Eclipse Mountain Collector's Edition
