CVE-2011-4162 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.6% (pctl 94)
Patch early
A public exploit exists.
Description
The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a long SidString argument.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.65% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-12-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| hp | protecttools device access manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HP Device Access Manager for HP ProtectTools 5.0/6.0 - Heap Memory Corruption | 2011-12-02 |
References
- http://marc.info/?l=bugtraq&m=132284686204608&w=2
- http://marc.info/?l=bugtraq&m=134152032516062&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71600
- https://www.htbridge.ch/advisory/heap_memory_corruption_in_hp_device_access_manager_for_protect_tools_information_store.html
- http://marc.info/?l=bugtraq&m=132284686204608&w=2
- http://marc.info/?l=bugtraq&m=134152032516062&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71600
- https://www.htbridge.ch/advisory/heap_memory_corruption_in_hp_device_access_manager_for_protect_tools_information_store.html
→ the Explorer · watch your stack · NVD