PT-2022-4714 · Hewlett Packard · Hp Performance Tune-Up+1
Published
2022-09-06
·
Updated
2022-12-15
·
CVE-2022-38395
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HP Support Assistant version 9
Description
The issue is related to a DLL hijacking vulnerability in HP Support Assistant, which uses HP Performance Tune-up as a diagnostic tool. This vulnerability can be exploited by an attacker to elevate privileges when Fusion launches the HP Performance Tune-up. The exploitation is possible if the attacker has already gained initial access to the vulnerable system.
Recommendations
For HP Support Assistant version 9, update to the latest version through the Microsoft Store.
As a temporary workaround, consider disabling the HP Performance Tune-up tool until a patch is available.
Restrict access to the Fusion module to minimize the risk of exploitation.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Performance Tune-Up
Hp Support Assistant