Impact
A software buffer overflow in the kernel driver for HP Sure Click can be triggered by a local user. The overflow permits overwriting critical kernel memory, potentially allowing the attacker to elevate privileges or execute arbitrary code with kernel‑level rights. The vulnerability is categorized as CWE‑122, a classic buffer overflow weakness that can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
HP Inc products HP Sure Click Enterprise, HP Wolf Pro Security, HP Wolf Pro Security Edition and HP Wolf Security for Business are affected. All versions released before version 4.4.33 contain the flaw; the vendor has issued version 4.4.33 as the fix.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity. No EPSS score is available, making it unclear how frequently this flaw is targeted in the wild, and it is not listed in the CISA KEV catalog. The attack vector is inferred to be local, as the flaw requires a user with the ability to run processes within the affected system. If actively exploited, local privilege escalation could allow complete takeover of the machine from the perspective of the attacker.
OpenCVE Enrichment