Executive brief
A security vulnerability has been identified in the installer software for certain HP Docking Stations. This software is used to manage hardware accessories on HP computers. If exploited, a malicious user with local access to a computer could gain higher-level system privileges or run unauthorized commands, potentially compromising the security of the entire device.
Technical details
The vulnerability is classified as CWE-379 (Creation of Temporary File in Directory with Insecure Permissions) within the HP Accessory WMI Provider installer. An attacker with local access and low privileges could exploit insecure file permissions during the installation process to escalate their privileges to a higher level or execute arbitrary code. The attack requires specific timing (high complexity) and some user interaction. HP has released software updates (version 1.4.11.0 or later) to mitigate this issue.
Affected products
- HP Inc. HP Accessory WMI Provider installer for HP Docking Stations versions prior to 1.4.11.0
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory