← Vulnerability feed

Vulnerability record · CVE-2009-0714 · published 14 May 2009

CVE-2009-0714: HP Data Protector Express dpwinsup Module Memory Disclosure and DoS

Hp · Data Protector Express

An unspecified flaw in the dpwinsup module (dpwinsup.dll) of HP Data Protector Express and Express SSE 3.x and 4.x lets remote attackers send crafted packets that crash the application or read portions of memory. The record gives no root cause detail, so the exact coding error is unknown.

7.2 CVSS 2.0 High EPSS 52% · top 1.1%
7.2CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityPublic exploit code exists and the flaw allows both memory disclosure and denial of service, though the record lacks root cause detail and the CVSS vector is inconsistent with the remote attack description.

What it is

An unspecified flaw in the dpwinsup module (dpwinsup.dll) of HP Data Protector Express and Express SSE 3.x and 4.x lets remote attackers send crafted packets that crash the application or read portions of memory. The record gives no root cause detail, so the exact coding error is unknown.

Impact

An attacker can cause a denial of service by crashing dpwingad.exe and can read portions of process memory, potentially exposing sensitive data handled by the backup service.

Attack surface

Reached remotely over the network via crafted packets to the affected service, per the description. The CVSS 2.0 vector is AV:L, which conflicts with the remote-attacker wording, and no authentication or user interaction requirement is stated.

Exploitation

Not listed in CISA KEV, but EPSS is 0.51612 (98.9th percentile) and two Exploit-DB entries (9006, 9007) are referenced, indicating public exploit code exists.

What to do

  • Upgrade HP Data Protector Express and Express SSE to 3.x build 47065 or later, or 4.x build 46537 or later, per the HP advisory.
  • If patching is not possible, restrict network access to the dpwingad service to trusted management hosts only.
  • Block or filter the service port at network boundaries and segment backup infrastructure from general user networks.
  • Monitor the vendor advisory for updated builds and apply them as they are released.

Detection

  • Monitor for crashes or unexpected restarts of dpwingad.exe and alert on repeated failures.
  • Inspect network traffic to the Data Protector Express service for malformed or unusually sized packets.
  • Review application and Windows event logs for faulting module dpwinsup.dll.
  • Watch for known Exploit-DB 9006/9007 payload patterns against the service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0714 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2009-0714), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.