The HP Quick Launch Button (QLB) has a nice Remote Execution of Arbitrary Code, Gain Privileged Access vulnerability.
HP Compaq business notebook PCs and HP Pavilion and Compaq Presario consumer notebook PCs all ship with Quick Launch Button (QLB) software preinstalled.
A potential security vulnerability has been identified with the HP Quick Launch Button (QLB) software running on Windows. The vulnerability could be exploited remotely to execute arbitrary code or to gain privileged access. [1]
Grab the patch from HP SoftPaq SP38166
This package provides a critical security update for HP Quick Launch Buttons on the supported notebook models and operating systems. This patch removes a security vulnerability by disabling HP Info Center. [2]
And you will need to apply the patch because: Removing or un-installing Quick Launch Button software does not eliminate the vulnerability. [1]
[1] ESB-2007.1018 — [Win] — HP Quick Launch Button (QLB) Running on Windows, Remote Execution of Arbitrary Code, Gain Privileged Access (2007-DEC-17) [AUSCERT]
[2] HP Quick Launch Buttons Critical Security Update 1.00 REV: A (2007-DEC-12) [HP]
[3] Got a HP laptop and running windows? Time to patch! (2007-DEC-19) [SANS]










