Impact
The HP Fan Control App contains a flaw that may allow a local attacker to elevate privileges on the affected machine. The weakness is classified as CWE-428, which involves improper handling or validation of runtime configuration data that can be exploited to gain higher privileges. If successfully triggered, an attacker could execute code with elevated rights, potentially compromising system integrity and confidentiality.
Affected Systems
The vulnerability affects HP Inc.'s HP Fan Control App running on Windows systems. No specific version information is provided, indicating that earlier releases prior to the patched update may be vulnerable. The CPE string confirms the product is Windows‑based.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity for local privilege escalation. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local: a user with some level of access to the machine can manipulate the application to trigger the escalation. Because no remote component is required, the risk is confined to systems where the app is installed.
OpenCVE Enrichment