Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HP Software Update RulesEngine.dll控件远程文件覆盖漏洞
Vulnerability Description
HP Software Update是美国HP公司所研发的一套在笔记本电脑中自动安装系统升级和系统补丁包的软件。 HP Software Updates所带的ActiveX控件实现上存在漏洞,远程攻击者可能利用此漏洞访问或破坏用户系统上的任意文件。 HP Software Updates所安装的RulesEngine.dll控件(CLSID:7CB9D4F5-C492-42A4-93B1-3F7D6946470D,默认路径C:\Program Files\Hewlett-Packard\eSupportD
CVSS Information
N/A
Vulnerability Type
N/A