Executive brief
A security vulnerability has been identified in the HP One Agent software installed on various HP PC products. This software is used for system management and support. If exploited, an attacker with local access to the computer could gain elevated administrative privileges or cause the system to crash, potentially leading to unauthorized data access or operational downtime.
Technical details
HP One Agent is vulnerable to an uncontrolled search path element (CWE-427), which can lead to privilege escalation or a denial of service. The vulnerability allows a local attacker with low privileges to execute arbitrary code with higher privileges or disrupt system services by placing a malicious file in a location searched by the application. This issue affects various HP PC products running the One Agent software. HP has released software updates to mitigate these vulnerabilities, and users are advised to apply the latest patches from the vendor.
Affected products
- HP Inc. One Agent All versions prior to the mitigation update
Timeline
- 2026-06-15: disclosed
- 2026-06-15: advisory