First published: Wed Jan 23 2008(Updated: )
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Virtual Rooms | =1.0.0.100 | |
ActiveX |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0437 has a critical severity level due to its potential for remote code execution.
To fix CVE-2008-0437, update the HP Virtual Rooms software to a secured version that addresses the buffer overflow vulnerabilities.
Users of HP Virtual Rooms version 1.0.0.100 and systems utilizing Microsoft ActiveX may be affected by CVE-2008-0437.
CVE-2008-0437 allows remote attackers to execute arbitrary code through crafted long property values.
Disabling or removing the affected ActiveX control can serve as a temporary workaround for CVE-2008-0437.