On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

December 14th, 2007

HP confirms gaping backdoor on 82 laptop models

Posted by Ryan Naraine @ 9:10 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Microsoft, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research

Tags: Hewlett-Packard Co., Laptop Computer, Laptop Model, Notebooks, Hardware, Notebooks & Tablets, Ryan Naraine

HP confirms gaping backdoor on 82 laptop modelsComputer maker Hewlett Packard has fessed up to a gaping security hole on more than 80 laptop models, warning that the backdoor could users at risk of drive-by code execution attacks.

An advisory from HP lists 82 laptop models as vulnerable to the ActiveX vulnerability found on the HP Info Center software.   The issue is rated “critical” and HP laptop owners should be aware that public exploit code that provides a roadmap for exploiting the hole is circulating around the Internet.

A successful exploit simply requires that the laptop owner is lured to a malicious Web site while using Microsoft’s Internet Explorer.  The risks include remote code execution, remote system registry read/write access and remote shell command execution.

It affects laptops running Windows 2000, Windows XP and Windows Vista.

[ SEE: There’s a hole in your laptop, dear HP, dear HP ]

The vulnerable ActiveX control is identified as HPInfoDLL.dll, which is marked as “Safe for Scripting” by default.

HP issued what could best be described as an interim patch that must be manually applied on vulnerable machines.   It does not patch the vulnerability but instead disables the HP Info Center software.Instructions on applying the fix are available at the bottom of HP’s advisory.

ALSO SEE:  Zero-day flaw haunts HP laptop models

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 9 Talkback(s)
Computer companies emulating MS backdoors
One of the troubling aspects is the amount of malware being installed on PCs by the big-name vendors. Most operate under the guise of "monitoring" the PC and reporting problems back to their homebase.... (Read the rest)
Posted by: terry flores Posted on: 12/17/07 You are currently: a Guest | | Terms of Use
HP Isn't The Problem  goodcomputing | 12/14/07
YEAH GREAT POST!!!!!  NonZealot | 12/14/07
Common Sense is not your strong point is it?  k12IT | 12/14/07
Prove that OS X isn't hack proof!  NonZealot | 12/14/07
First I'd like proof....  DCMann | 12/14/07
BUT I SPECIFICALLY SAID OS X ISN'T PERFECT!!!!!!  NonZealot | 12/14/07
Don't pay any attention to the professional Troll  MarcB_z | 12/15/07
Just remove it  DarthRidiculous | 12/15/07
Computer companies emulating MS backdoors  terry flores | 12/17/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline