First published: Wed Jun 04 2008(Updated: )
The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Instant Support | <=1.0.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0953 is considered a critical vulnerability as it allows remote attackers to execute arbitrary programs.
To fix CVE-2008-0953, upgrade to HP Instant Support version 1.0.0.24 or later.
CVE-2008-0953 affects all versions of HP Instant Support prior to 1.0.0.24.
CVE-2008-0953 is a remote code execution vulnerability.
Yes, CVE-2008-0953 can be exploited remotely, potentially without any user interaction.