CVE-2011-0922
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 64%
from disclosure to weapon109 days
Published on NVDFeb 9
1st PoC+109d
metasploit+266d
exploitation probability
64%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/27271unverifiedexploitdbwww.exploit-db.com/exploits/19288unverifiedexploitdbwww.exploit-db.com/exploits/17345unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hphttp://marc.info/?l=bugtraq&m=130391284726795&w=2http://www.securityfocus.com/archive/1/516272/100/0/threadedhttp://www.securityfocus.com/bid/46234http://www.vupen.com/english/advisories/2011/0308http://zerodayinitiative.com/advisories/ZDI-11-056/