Dec 272007
HP Releases Fix for the Update Service Flaw
Posted by: Sierra in HP
Porkythepig is not a trustful nickname but the Polish researcher who uses it has discovered several bugs in HP’s updating service that could be used to execute remote malicious code in order to get control over some HP and HP Compaq laptop models.He demonstrated how the ActiveX control from the update service can be used to leave all affected laptops unbootable.
All this fuss comes from an update provided by HP to fix the flaws discovered in a patch-management program bundled with its PCs and peripherals.
The hacking attacks can easily block the systems and only those PCs that have restoring media have some chances to recover.
Secunia has rated this vulnerability as highly critical, and after intensive efforts, HP has published new instructions for the HP laptops’ users about how to run the Software Update in order to disable the ActiveX control.






Comments