Description
A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.
Published: 2026-10-08
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Local privilege escalation or arbitrary code execution
Action: Update now
AI Analysis

Impact

A software buffer overflow in the kernel driver for HP Sure Click can be triggered by a local user. The overflow permits overwriting critical kernel memory, potentially allowing the attacker to elevate privileges or execute arbitrary code with kernel‑level rights. The vulnerability is categorized as CWE‑122, a classic buffer overflow weakness that can compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

HP Inc products HP Sure Click Enterprise, HP Wolf Pro Security, HP Wolf Pro Security Edition and HP Wolf Security for Business are affected. All versions released before version 4.4.33 contain the flaw; the vendor has issued version 4.4.33 as the fix.

Risk and Exploitability

The CVSS score of 6.4 indicates a medium severity. No EPSS score is available, making it unclear how frequently this flaw is targeted in the wild, and it is not listed in the CISA KEV catalog. The attack vector is inferred to be local, as the flaw requires a user with the ability to run processes within the affected system. If actively exploited, local privilege escalation could allow complete takeover of the machine from the perspective of the attacker.

Generated by OpenCVE AI on October 8, 2026 at 17:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the HP Sure Click version 4.4.33 update or newer
  • Reboot the system to ensure the updated kernel is loaded
  • Limit local user privileges or disable HP Sure Click if it is not required

Generated by OpenCVE AI on October 8, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description HP has released a fix to mitigate the potential vulnerability in software that includes HP Sure Click. A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.

Thu, 08 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description HP has released a fix to mitigate the potential vulnerability in software that includes HP Sure Click.
Title HP Sure Click Kernel Buffer Overflow
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-10-08T16:37:52.197Z

Reserved: 2026-10-06T16:28:52.187Z

Link: CVE-2026-106177

cve-icon Vulnrichment

Updated: 2026-10-08T16:37:48.869Z

cve-icon NVD

Status : Received

Published: 2026-10-08T16:17:01.777

Modified: 2026-10-08T17:17:13.297

Link: CVE-2026-106177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:00:18Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow