Vulnerable Systems:
* Hewlett-Packard Data Protector
Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DBServer.exe process which listens by default on TCP port 19813. While parsing a request, the process trusts a user-supplied 32-bit length value and uses it within a memory operation. By specifying large enough values in a packet sent to the service, a remote attacker can execute arbitrary code under the context of the SYSTEM user.
Workaround:
To mitigate this vulnerability an administrator could restrict communication with this service to known client IP addresses.
Disclosure Timeline:
2010-09-24 - Vulnerability reported to vendor
2011-03-23 - Coordinated public release of advisory