The Register® — Biting the hand that feeds IT

Feeds

'Highly critical' security bug bites HP Virtual Rooms

More ActiveX insecurity

Agentless Backup is Not a Myth

A security researcher has uncovered a serious security bug in a Hewlett-Packard website used to host virtual meetings that could allow an attacker to remotely run malicious code on the machines of people who use the service.

The vulnerability in HP Virtual Rooms resides in the ActiveX client used to install the service on users' PCs, according to this advisory posted Tuesday on the Full-Disclosure mail list. Vulnerability tracking service Secunia rates it "highly critical," because it can be used by attackers to compromise a user's machine.

Over the past year, security slip-ups at HP have put its laptop customers at risk for at least three attacks. Two of them allowed attackers to remotely run malicious code if they could lure victims to a booby-trapped website. A third bug allowed miscreants to render the machine unbootable. The flaws, which HP has since fixed, resided in software that comes pre-installed on machines and is typically used to help users install updates and trouble shoot technical problems.

HP Virtual Rooms is a package of online tools for business collaboration, training and support. Participants can enter rooms to discuss particular projects and collaborate in real-time with colleagues on spreadsheets, video presentations and other jobs.

The bug in HP Virtual Rooms is found in hpvirtualrooms14.dll, which is used to install software needed to make the service work on an end-user's machine. It is likely used only during the installation process, so one possible work-around involves setting the killbit for the control.

The bug was reported by Elazar Broad. ®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments

Highly critical ?

Do you mean highly critical as in complaining about the muck in here ?

Brown leather, yes, the one with the road map inside, thanks

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?