CVE-2008-0953: Critical severity hp instant support vulnerability
Published Jun 4, 2008
·Updated
The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.
Affected Software
1 affected component
HP Instant Support<=1.0.0.23
Remediation
Patch Available
Event History
Jun 4, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0953?
CVE-2008-0953 is considered a critical vulnerability as it allows remote attackers to execute arbitrary programs.
2
How do I fix CVE-2008-0953?
To fix CVE-2008-0953, upgrade to HP Instant Support version 1.0.0.24 or later.
3
What systems are affected by CVE-2008-0953?
CVE-2008-0953 affects all versions of HP Instant Support prior to 1.0.0.24.
4
What type of vulnerability is CVE-2008-0953?
CVE-2008-0953 is a remote code execution vulnerability.
5
Can CVE-2008-0953 be exploited without user interaction?
Yes, CVE-2008-0953 can be exploited remotely, potentially without any user interaction.