Plantronics Desktop Hub LPE# CVE-2024-27460 - Plantronics Desktop Hub LPE
Arbitrary File Delete to SYSTEM. Majority of code is based on the referenced PoC by @filip_dragovic. Thanks @filip_dragovic & @k0zmer :)
Blog Post: [https://mantodeasecurity.de/en/2024/05/cve-2024-27460-plantronics-hub-lpe](https://mantodeasecurity.de/en/2024/05/cve-2024-27460-plantronics-hub-lpe/)
## References
- https://support.hp.com/us-en/document/ish_9869257-9869285-16/hpsbpy03895
- https://github.com/Wh04m1001/CVE-2023-20178
- [@filip_dragovic](https://twitter.com/filip_dragovic)
- [@k0zmer](https://twitter.com/k0zmer)
[4.0K] /data/pocs/4144b2d56eab120a5bf67b858b3d2e79a7e03740
├── [4.0K] CVE-2024-27460
│ ├── [558K] cmd.rbs
│ ├── [ 13K] CVE-2024-27460.cpp
│ ├── [6.7K] CVE-2024-27460.vcxproj
│ ├── [1.5K] CVE-2024-27460.vcxproj.filters
│ ├── [2.3K] def.h
│ ├── [4.1K] FileOpLock.cpp
│ ├── [ 946] FileOpLock.h
│ ├── [184K] Msi_Rollback.msi
│ ├── [ 497] resource.h
│ └── [1.6K] resource.rc
├── [1.4K] CVE-2024-27460.sln
└── [ 582] README.md
1 directory, 12 files