Impact
A vulnerability in HP Support Assistant versions older than 9.55.10.0 permits a local attacker to gain higher privileges on a machine by exploiting insufficient access controls. The flaw is a classic improper authorization issue (CWE‑269) that could allow an attacker who has local login rights to execute privileged operations or modify system configuration, potentially compromising the confidentiality, integrity, or availability of the affected system.
Affected Systems
The affected product is HP Support Assistant from HP Inc. All installations running any version earlier than 9.55.10.0 are susceptible.
Risk and Exploitability
The CVSS score of 7.3 classifies this as a high‑severity vulnerability. No EPSS data is available, so the exploitation likelihood remains unclear, and the vulnerability has not been listed in the CISA KEV catalog. The attack requires local access, which is inferred because the description mentions a local attacker; no remote exploit mechanism is cited.
OpenCVE Enrichment