Skip to main content

HP Releases Security Update for a Critical Vulnerability in HP Support Assistant

HP releases security update to address a critical privilege escalation vulnerability in HP Support Assistant

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

HP releases security update to address a critical privilege escalation vulnerability in HP Support Assistant


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

HP has released a security bulletin for a Critical vulnerability in HP Support Assistant, tracked as CVE-2022-38395. This vulnerability could allow an attacker to exploit the DLL hijacking vulnerability and perform privilege escalation when Fusion launches the HP Performance Tune-up. An attacker could exploit this vulnerability to take control of an affected system.


Remediation advice

Affected organisations are advised to review HP's Security Bulletin HPSBHF03809 and apply any necessary updates.



Last edited: 8 September 2022 4:10 pm