Vulnerability record · CVE-2011-4789 · published 13 January 2012
CVE-2011-4789: HP LoadRunner magentservice.exe stack buffer overflow
Hp · Diagnostics
HP LoadRunner 11.00 before patch 4 contains a stack-based buffer overflow in magentservice.exe, triggered by a crafted size value in a packet. A remote, unauthenticated attacker can reach the service and corrupt memory, making this a full-impact code execution flaw. The record notes the product was initially misattributed to HP Diagnostics Server, but HP confirmed the vulnerable product is LoadRunner.
Description
Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attackers to execute arbitrary code via a crafted size value in a packet. NOTE: it was originally reported that the affected product is HP Diagnostics Server, but HP states that "the vulnerable product is actually HP LoadRunner."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote unauthenticated code execution with a CVSS 2.0 score of 10 and high EPSS, though no confirmed in-the-wild exploitation is recorded.
What it is
HP LoadRunner 11.00 before patch 4 contains a stack-based buffer overflow in magentservice.exe, triggered by a crafted size value in a packet. A remote, unauthenticated attacker can reach the service and corrupt memory, making this a full-impact code execution flaw. The record notes the product was initially misattributed to HP Diagnostics Server, but HP confirmed the vulnerable product is LoadRunner.
Impact
Successful exploitation lets a remote attacker execute arbitrary code with the privileges of the magentservice.exe process, giving full control of confidentiality, integrity and availability on the host.
Attack surface
The flaw is network-reachable (AV:N) with no authentication (Au:N) and low attack complexity (AC:L), so any host exposing the LoadRunner agent service is directly exposed. No user interaction is indicated by the vector or description.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.64 (99th percentile), indicating elevated likelihood of attempted exploitation. Reference tags are empty, so no public exploit or PoC status can be confirmed from this record.
What to do
- Apply HP LoadRunner 11.00 patch 4 or later, or upgrade to a supported LoadRunner release.
- Restrict network access to magentservice.exe (default TCP 50500) to trusted management hosts only.
- Do not expose the LoadRunner agent service to untrusted networks or the internet.
- Monitor HP advisories for the corrected product attribution and any follow-up patches.
- Where the service is not required, disable or uninstall the LoadRunner agent component.
Detection
- Alert on unexpected or oversized packets to the magentservice.exe listening port.
- Monitor for crashes or restarts of magentservice.exe and related LoadRunner processes.
- Watch for child processes spawned by magentservice.exe, which would indicate successful code execution.
- Review network logs for scanning or connection attempts to the agent port from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-4789 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4789), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.