Vulnerability record · CVE-2009-0714 · published 14 May 2009
CVE-2009-0714: HP Data Protector Express dpwinsup Module Memory Disclosure and DoS
Hp · Data Protector Express
An unspecified flaw in the dpwinsup module (dpwinsup.dll) of HP Data Protector Express and Express SSE 3.x and 4.x lets remote attackers send crafted packets that crash the application or read portions of memory. The record gives no root cause detail, so the exact coding error is unknown.
Description
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityPublic exploit code exists and the flaw allows both memory disclosure and denial of service, though the record lacks root cause detail and the CVSS vector is inconsistent with the remote attack description.
What it is
An unspecified flaw in the dpwinsup module (dpwinsup.dll) of HP Data Protector Express and Express SSE 3.x and 4.x lets remote attackers send crafted packets that crash the application or read portions of memory. The record gives no root cause detail, so the exact coding error is unknown.
Impact
An attacker can cause a denial of service by crashing dpwingad.exe and can read portions of process memory, potentially exposing sensitive data handled by the backup service.
Attack surface
Reached remotely over the network via crafted packets to the affected service, per the description. The CVSS 2.0 vector is AV:L, which conflicts with the remote-attacker wording, and no authentication or user interaction requirement is stated.
Exploitation
Not listed in CISA KEV, but EPSS is 0.51612 (98.9th percentile) and two Exploit-DB entries (9006, 9007) are referenced, indicating public exploit code exists.
What to do
- Upgrade HP Data Protector Express and Express SSE to 3.x build 47065 or later, or 4.x build 46537 or later, per the HP advisory.
- If patching is not possible, restrict network access to the dpwingad service to trusted management hosts only.
- Block or filter the service port at network boundaries and segment backup infrastructure from general user networks.
- Monitor the vendor advisory for updated builds and apply them as they are released.
Detection
- Monitor for crashes or unexpected restarts of dpwingad.exe and alert on repeated failures.
- Inspect network traffic to the Data Protector Express service for malformed or unusually sized packets.
- Review application and Windows event logs for faulting module dpwinsup.dll.
- Watch for known Exploit-DB 9006/9007 payload patterns against the service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0714 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0714), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.