Multiple flaws found in HP Software Update tool

By Liam Tung, ZDNet Australia
Tuesday, April 29, 2008 11:58 AM

HP’s Software Update Tool was found to contain flaws which could lead to remote code execution or the leakage of sensitive information stored on a PC.

The offending component of the HP Software Update application is the HPeDiag ActiveX control, which checks for and downloads security, firmware, software and driver updates.

The flaw affects any HP PCs, or any PC connected to HP scanners, printers and cameras that contain a version of the update.

Tan Chew Keong from Vuln.sg, who advised HP of the flaw in March, said the vulnerable ActiveX controls were installed as part of HP Software Update version 3.0.2.991 when the user installs the Windows software suite for HP colour LaserJet 2820/2840.

However, according to HP's security advisory, the flaw affects a larger set of products, including scanners, printers, cameras and PCs that use HP Software Update. Updates v4.000.009.002 or earlier running on Windows may be exposed to the vulnerability but should be resolved for PCs with update v4.000.010.008 or higher.

"A successful exploit requires that the user is tricked into visiting a malicious Web site using IE6 or earlier. If the user uses IE7, he must first be convinced into allowing the ActiveX control to run," Tan said.

HP has not clarified in its advisory which versions of Internet Explorer are vulnerable to such an attack; however, it does explain how to resolve the problem.

HP has not advised customers to disable ActiveX in Internet Explorer, however USCert and Tan recommend doing so.

The flawed application is the second threat that HP has exposed its customers to this month. HP previously shipped malware-infected USB drives for its ProLiant servers.

HP was unable to respond to ZDNet Australia's questions at the time of writing.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Hands-on programming: Extract plain text from documents with Syncfusion's components

Web Development

Justin James recently tried Syncfusion's Essential DocIO and Essential PDF to help him extract text from documents that he downloaded from the Internet. Here's the code that he wrote to get the plain text from the document.


Read more »



Will technology divide us further?

Blog thumbnail

So I finally watched 2012 over the weekend, but the film left me feeling extremely agitated.

The possibility that the world may meet its watery end in three years didn't..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web