Warning: security gap in HP Support Assistant

HP Assistant is a useful utility provided by HP so that you can download and install necessary firmware and software, check performance, and run some basic troubleshooting solutions, among others.hplaptop

However, the company warned that it had discovered a security hole in the app that could lead to privilege escalation using a method DLL hijacking.

HP has given the new security vulnerability a high severity rating with a CVSS v3.1 base score of 8,2.

The είναι στο διαγνωστικό Performance Tune-up. In its security bulletin, HP he explains the problem:

Privilege Escalation in HP Support Assistant

HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to of HP Performance Tune-up. However, it is possible for an attacker to exploit the vulnerability with DLL hijacking and elevate privileges when Fusion launches HP Performance Tune-up.

HP also lists the vulnerable software versions to avoid:

  • HP Support Assistant versions earlier than 9.11
  • Fusion versions earlier than 1.38.2601.0

So, it is recommended that everyone using HP computers should download and install it 9.11 of HP Support Assistant by official website of the company.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
HP Support Assistant, hp, iguru

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).