module
HP Easy Printer Care XMLSimpleAccessor Class ActiveX Control Remote Code Execution
Disclosed | Created |
---|---|
Aug 16, 2011 | May 30, 2018 |
Disclosed
Aug 16, 2011
Created
May 30, 2018
Description
This module allows remote attackers to place arbitrary files on a users file
system by abusing via Directory Traversal attack the "saveXML" method from the
"XMLSimpleAccessor" class in the HP Easy Printer HPTicketMgr.dll ActiveX Control
(HPTicketMgr.dll 2.7.2.0).
Code execution can be achieved by first uploading the payload to the remote
machine embeddeding a vbs file, and then upload another mof file, which enables Windows
Management Instrumentation service to execute the vbs. Please note that this
module currently only works for Windows before Vista.
system by abusing via Directory Traversal attack the "saveXML" method from the
"XMLSimpleAccessor" class in the HP Easy Printer HPTicketMgr.dll ActiveX Control
(HPTicketMgr.dll 2.7.2.0).
Code execution can be achieved by first uploading the payload to the remote
machine embeddeding a vbs file, and then upload another mof file, which enables Windows
Management Instrumentation service to execute the vbs. Please note that this
module currently only works for Windows before Vista.
Authors
Andrea Micalizzi
juan vazquez juan.vazquez@metasploit.com
juan vazquez juan.vazquez@metasploit.com
Platform
Windows
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.