>> HP Software Update ActiveX Control Code Execution and File Corruption
Title : HP Software Update ActiveX Control Code Execution and File Corruption VUPEN ID : VUPEN/ADV-2007-4271 CVE ID : CVE-2007-6506
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-20
Technical Description
Multiple vulnerabilities have been identified in HP Software Update, which could be exploited by attackers to corrupt arbitrary files or compromise a vulnerable system.
The first issue is caused by a design error in the "RulesEngine.dll" ActiveX Control that includes the insecure "SaveToFile()" method, which could be exploited by attackers to overwrite arbitrary files on a vulnerable system by tricking a user into visiting a malicious web page.
The second vulnerability is caused by an unspecified error which could allow attackers to execute arbitrary code.