Vulnerability record · CVE-2011-2404 · published 11 August 2011
CVE-2011-2404: HP Easy Printer Care ActiveX control allows remote code download and execution
Hp · Easy Printer Care Software
An ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier lets a remote attacker cause an arbitrary program to be downloaded to a client machine and executed. The exact vectors are unspecified in the record, but the flaw is a code injection issue reachable over the network without authentication.
Description
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-4786 and CVE-2011-4787.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a very high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.
What it is
An ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier lets a remote attacker cause an arbitrary program to be downloaded to a client machine and executed. The exact vectors are unspecified in the record, but the flaw is a code injection issue reachable over the network without authentication.
Impact
An attacker can place and run arbitrary code on a victim's Windows client, giving full control of that machine under the user's privileges.
Attack surface
Reached over the network (AV:N) with no authentication (Au:N) and low complexity (AC:L); the description does not state whether user interaction such as visiting a malicious page or opening a crafted file is required, so that detail is missing.
Exploitation
Not listed in CISA KEV and no public exploit is confirmed by the reference tags, but EPSS is very high (0.7374, 99.45th percentile), indicating strong predicted likelihood of exploitation.
What to do
- Apply the HP vendor advisory fix or upgrade Easy Printer Care Software beyond version 2.5; if no supported fix exists, remove the product.
- Disable or kill the vulnerable HPTicketMgr.dll ActiveX control via Internet Explorer kill-bit settings.
- Restrict or block outbound and inbound access to the affected control's hosting paths and untrusted web content at the network boundary.
- Enforce least privilege and application allowlisting so downloaded executables cannot run on client machines.
Detection
- Monitor for unexpected executable downloads and process creation spawned from browser or ActiveX host processes.
- Alert on HPTicketMgr.dll being loaded or instantiated outside expected HP Easy Printer Care usage.
- Review proxy and DNS logs for clients contacting untrusted hosts that serve the malicious control content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-2404 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-2404), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.