HP.LoadRunner.XUpload.MakeHttpRequest.ActiveX.Control.Access

description-logoDescription

This indicates an attack attempt against an arbitrary file download and execute vulnerability in HP LoadRunner.
The vulnerability is caused by an error when the Persits.XUpload ActiveX control handles a specially crafted web page. It allows a remote attacker to overwrite credential files on the target system.

affected-products-logoAffected Products

HP Mercury LoadRunner Agent 9.5

Impact logoImpact

System Compromise
Security Bypass

recomended-action-logoRecommended Actions

Set the kill bit for the CLSID {E87F6C8E-16C0-11D3-BEF7-009027438003}.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)