|
|
| |
Credit:
The information has been provided by Andrea Micalizzi aka rgod.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-12-014/
|
| |
Vulnerable Systems:
* Hewlett-Packard Easy Printer Care
User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the XMLSimpleAccessor ActiveX control (CLSID: {466576F3-19B6-4FF1-BD48-3E0E1BFB96E9}). By passing an overlong string to the LoadXML() method it is possible to trigger a heap corruption vulnerability. A remote attacker could exploit this vulnerability to execute arbitrary code on the affected machine under the context of the user running the Internet Explorer process.
Patch Availability:
Hewlett-Packard has issued an update to correct this vulnerability. More details can be found at:
http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c02949847
CVE Information:
CVE-2011-4787
Disclosure Timeline:
2011-04-04 - Vulnerability reported to vendor
2012-01-12 - Coordinated public release of advisory
|
|
|