Impact
The vulnerability is a CWE‑319 flaw, involving improper handling of sensitive information. It may allow an attacker to elevate privileges on the system. It is reported in HP Easy Start for macOS versions prior to 2.16.7.260722. The advisory does not detail how the flaw is triggered, but any successful exploitation could grant an attacker higher‑level access.
Affected Systems
The affected product is HP Easy Start for macOS from HP Inc. Versions before 2.16.7.260722 are vulnerable; users should verify the installed version and ensure it is updated to this release or newer.
Risk and Exploitability
The CVSS base score of 7.7 classifies this as a high‑severity issue. The EPSS score is not provided, so the current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV, indicating no documented active exploitation. The advisory does not specify the attack vector, so it could involve local or other means. Until a patch is applied, this should be treated as a high‑risk item.
OpenCVE Enrichment