First published: Thu Feb 08 2007(Updated: )
HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Network Node Manager i | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0819 is classified as a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2007-0819, limit the access permissions for the %PROGRAMFILES%\HP OpenView directory tree to prevent unauthorized users from gaining control.
HP Network Node Manager versions 7.50, 7.51, and 7.53 are affected by CVE-2007-0819.
Yes, CVE-2007-0819 can be exploited locally by users with access to execute malicious files in the HP OpenView directory.
CVE-2007-0819 could be exploited for privilege escalation through the execution of Trojan horse executables or altered ActiveX components.