Impact
A local attacker can leverage insufficient access controls in HP Support Assistant versions before 9.53.2.0 to increase privileges. This flaw can grant a user higher authority within the local system, potentially allowing them to execute restricted operations or manipulate system resources, thereby impacting confidentiality, integrity, and availability of the host.
Affected Systems
HP Inc. HP Support Assistant is affected, specifically all releases older than 9.53.2.0. No specific hardware models are specified, so the issue applies broadly to all environments running the vulnerable version of the application.
Risk and Exploitability
The CVSS score of 7.3 indicates a high risk for a local attacker. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the vulnerability is listed outside the CISA KEV catalog. Based on the description, the attack vector is local; a threat actor must have physical or local administrative access to the machine. The user does not need to bypass any network controls, but must be able to run applications with the user’s rights.
OpenCVE Enrichment