Feeds

'Highly critical' security bug bites HP Virtual Rooms

More ActiveX insecurity

The essential guide to IT transformation

A security researcher has uncovered a serious security bug in a Hewlett-Packard website used to host virtual meetings that could allow an attacker to remotely run malicious code on the machines of people who use the service.

The vulnerability in HP Virtual Rooms resides in the ActiveX client used to install the service on users' PCs, according to this advisory posted Tuesday on the Full-Disclosure mail list. Vulnerability tracking service Secunia rates it "highly critical," because it can be used by attackers to compromise a user's machine.

Over the past year, security slip-ups at HP have put its laptop customers at risk for at least three attacks. Two of them allowed attackers to remotely run malicious code if they could lure victims to a booby-trapped website. A third bug allowed miscreants to render the machine unbootable. The flaws, which HP has since fixed, resided in software that comes pre-installed on machines and is typically used to help users install updates and trouble shoot technical problems.

HP Virtual Rooms is a package of online tools for business collaboration, training and support. Participants can enter rooms to discuss particular projects and collaborate in real-time with colleagues on spreadsheets, video presentations and other jobs.

The bug in HP Virtual Rooms is found in hpvirtualrooms14.dll, which is used to install software needed to make the service work on an end-user's machine. It is likely used only during the installation process, so one possible work-around involves setting the killbit for the control.

The bug was reported by Elazar Broad. ®

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?