On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

December 11th, 2007

Zero-day flaw haunts HP laptop models

Posted by Ryan Naraine @ 3:10 pm

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Metasploit, Microsoft, Passwords, Patch Watch, Pen testing, Responsible disclosure, Spam and Phishing, Viruses and Worms, Vulnerability research, Windows Vista, Wireless, Zero-day attacks

Tags: Notebook, Hewlett-Packard Co., ActiveX Control, Laptop Computer, Flaw, Laptop Model, Notebooks, Hardware, Notebooks & Tablets, Ryan Naraine

Zero-day flaw haunts HP laptopsA zero-day hole is several major HP laptop models could provide an easy way for hackers to take complete control of Windows machines, according to a warning from an independent security researcher.

The researcher, known as “porkythepig,”  discovered the vulnerability in the HP Info Center software that’s preinstalled on multiple HP Compaq notebook series to allow one-touch access to features.

The skinny from a detailed advisory:

One of [the software's] ActiveX controls deployed by default by the vendor has three insecure methods that allow a malicious person to target the HP notebook machines for a remote code execution and remote registry manipulation based attacks.

[ ALSO SEE: There's a hole in your laptop, dear HP, dear HP ]

A successful exploit simply requires that the laptop owner is lured to a malicious Web site while using Microsoft’s Internet Explorer.  The risks include remote code execution, remote system registry read/write access and remote shell command execution.

The vulnerable ActiveX control is identified as HPInfoDLL.dll, which is marked as “Safe for Scripting” by default.

The exploit code, which has been posted to Milw0rm.com and BugTraq, includes a list of HP laptop models that are confirmed vulnerable.

The researcher also provides a Web page that detects if your HP machine is vulnerable (use at your own risk).

This is the second time this year that HP has run into security trouble with software that ships with its laptop models. Back in June, the company patched a very serious Help and Support Center vulnerability that put Windows XP machines at risk of code execution attacks.



		
	

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 46 Talkback(s)
170.224.163.33
I found the same mysterious IP address on my new HP dv9500 laptop. The ARIN WHOIS database lists the owner as IBM. I have no IBM software and have never visited an IBM website, so why this IP address... (Read the rest)
Posted by: SLRoberts Posted on: 12/31/07 You are currently: a Guest | | Terms of Use
HP Pavilion Notebook zv6130us and HP Info Center  Grayson Peddie | 12/12/07
This must be old news...  JCitizen | 12/12/07
RE: Zero-day flaw haunts HP laptop models  craig-wilson@... | 12/12/07
Rediculous statements..  Etch44 | 12/12/07
Agreed  Louis.Ross@... | 12/12/07
I'm still using more than half of those "craplets"  JCitizen | 12/12/07
RE: Zero-day flaw haunts HP laptop models  raviratlami | 12/12/07
No Worrys! The 64 bit O/S would have given you heaps of problems  pingu@... | 12/12/07
Probably correct for Vista x64 but..  JCitizen | 12/12/07
standard practice, thanks to the x64 driver issues that were out there...  shryko | 12/13/07
Overall flaws haunt HP laptop models  moxnix2 | 12/12/07
Compaq Craptops  Pony99CA | 12/12/07
Other makers have similar?  techboy_z | 12/12/07
Yep. IBM/Lenovo had a problem with Apcon~1.dll  pingu@... | 12/12/07
Windows Update  Mahegan | 12/12/07
Bloatware  smarmybastard | 12/12/07
Deleting Pre-Installed Software  Pony99CA | 12/12/07
Agreed, as I posted earlier I am still using allmost ...  JCitizen | 12/12/07
Your HP applications...  A_Pickle | 12/12/07
True, but to clarify, I am talking about 3rd party...  JCitizen | 12/12/07
Yes and no.  A_Pickle | 12/12/07
why they'd do a few things...  shryko | 12/13/07
saving money on programmers is why it bloats up...  shryko | 12/13/07
Yeh,one thing I can't stand  Louis.Ross@... | 12/12/07
It's grossely inaccurate as well...  JCitizen | 12/12/07
WindowZones will prevent all these vulnerabilities  rossv@... | 12/12/07
RE: Zero-day flaw haunts HP laptop models  phatkat | 12/12/07
On a side note...  Selvarin | 12/12/07
170.224.163.33  SLRoberts | 12/31/07
Already fixed last summer..  JCitizen | 12/12/07
HP, DELL, SONY, VAIO should stop installing useless & bloatware software!  qmlscycrajg | 12/12/07
Dell is cutting back, at least more than the others...  shryko | 12/13/07
OLD NEWS...TOO LATE! Way past zero day; sorry! (NT)  JCitizen | 12/12/07
Some companies let you order your computer without the crapware  bmerc | 12/12/07
ActiveX should never have been invented  MrViklund | 12/12/07
Should never have been invented  Mahegan | 12/12/07
reasonable concept... too bad they didn't think it through  shryko | 12/13/07
HP Laptop -Caught me  solan1000000@... | 12/12/07
A successful exploit lured to malicious website - sounds like WGA  Mahegan | 12/12/07
Zero-day *flaw*?  Justin James | 12/12/07
well that's a relief  james.faction | 12/12/07
I have HP 9543 Laptop!!!!  rgeiken@... | 12/13/07
Set the kill-bit & be done, for now...  wti | 12/13/07
QA?  John Musbach | 12/16/07
I just refuse to buy computers with crap ware...  mikifinaz1@... | 12/17/07
Worst computer I ever owned  YeaiBetYouDo | 12/17/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads