CVE-2007-5610: Critical severity HP Instant Support vulnerability
Published Jun 4, 2008
·Updated
The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to delete an arbitrary file via a full pathname in the argument.
Affected Software
1 affected component
HP Instant Support<=1.0.0.23
Remediation
Patch Available
Event History
Jun 4, 2008
CVE Published
08:32 PM
Jun 5, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5610?
CVE-2007-5610 is classified as a critical vulnerability due to its remote exploitation potential.
2
How do I fix CVE-2007-5610?
To mitigate CVE-2007-5610, update HP Instant Support to version 1.0.0.24 or later.
3
What does CVE-2007-5610 allow an attacker to do?
CVE-2007-5610 allows remote attackers to delete arbitrary files on the victim's system.
4
Which software is affected by CVE-2007-5610?
CVE-2007-5610 affects HP Instant Support versions prior to 1.0.0.24.
5
Is CVE-2007-5610 still a risk for users?
Yes, CVE-2007-5610 remains a risk for any users running vulnerable versions of HP Instant Support.