Executive brief
HP Support Assistant is a utility application that helps users manage and troubleshoot HP devices. A privilege escalation vulnerability in versions prior to 9.53.2.0 allows a local attacker to gain elevated system access due to insufficient access controls, potentially enabling unauthorized system modifications or data access.
Technical details
The vulnerability is a privilege escalation flaw caused by insufficient access controls in HP Support Assistant. It requires local access to the affected system to exploit. An authenticated local attacker can leverage this weakness to escalate their privileges and execute code with elevated system rights. The vulnerability affects all versions prior to 9.53.2.0, and patches are available in version 9.53.2.0 and later.
Affected products
- HP Support Assistant prior to 9.53.2.0
Timeline
- 2026-09-03: disclosed