Tuesday, October 15, 2024
HomeCVE/vulnerabilityHP Support Assistant High Severity Flaw Let Attackers Escalate Privileges

HP Support Assistant High Severity Flaw Let Attackers Escalate Privileges

Published on

Malware protection

HP patches a high-severity security flaw in the HP Support Assistant, which helps keep HP computer in working order by finding updates and providing troubleshooting tools. 

It’s a software tool that comes pre-installed on all HP laptops and desktop computers, including the Omen sub-brand. It carries out hardware diagnostic tests, dive deeper into technical specifications, check performance related metrics, and driver updates on HP devices.

The flaw is tracked as (CVE-2022-38395), with a high severity score of 8.2, which leads to privilege escalation vulnerability. The flaw was revealed by researchers at Secure D.

- Advertisement - SIEM as a Service

“It is possible for an attacker to exploit the DLL hijacking vulnerability and elevates privileges when Fusion launches the HP Performance Tune-up”, reads the advisory from HP

Thus, a DLL hijacking vulnerability triggered when the user launches HP Performance Tune-up within HP Support Assistant. This takes place when a threat actor places a DLL containing malicious code on the same folder as the abused executable, exploiting Windows’ logic to prioritize those libraries against DLLs in the System32 directory.

The subsystem that can trigger the DLL hijacking flaw

The subsystem that can trigger the DLL hijacking attack

In this case, the code that executes by loading the library assumes the privileges of the abused executable which is HP Support Assistant running with ‘SYSTEM’ privileges.

Affected Products

  • HP Support Assistant versions earlier than 9.11.
  • Fusion versions earlier than 1.38.2601.0.

Recommendations

HP advises the customers update to the latest version of HP Support Assistant that includes fixes for issues by turning on automatic updates in the HP Support Assistant settings. 

If the system has HP Support Assistant version 8x, it is recommended to upgrade to HP Support Assistant version 9 by going to the “About” section and “check for updates”. If the system has HP Support Assistant version 9, keep the Microsoft Store updates turned on so that the application is always kept up to date.

Download Free SWG – Secure Web Filtering – E-book

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Splunk Enterprise Vulnerabilities let Attackers Execute Remote Code

Splunk has disclosed multiple vulnerabilities affecting its Enterprise product, which could allow attackers to...

OilRig Hackers Exploiting Microsoft Exchange Server To Steal Login Details

Earth Simnavaz, an Iranian state-sponsored cyber espionage group, has recently intensified its attacks on...

CoreWarrior Malware Attacking Windows Machines From Dozens Of IP Address

Researchers recently analyzed a CoreWarrior malware sample, which spreads aggressively by creating numerous copies...

TrickMo Malware Targets Android Devices to Steal Unlock Patterns and PINs

The recent discovery of the TrickMo Banking Trojan variant by Cleafy has prompted further...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Splunk Enterprise Vulnerabilities let Attackers Execute Remote Code

Splunk has disclosed multiple vulnerabilities affecting its Enterprise product, which could allow attackers to...

OilRig Hackers Exploiting Microsoft Exchange Server To Steal Login Details

Earth Simnavaz, an Iranian state-sponsored cyber espionage group, has recently intensified its attacks on...

CoreWarrior Malware Attacking Windows Machines From Dozens Of IP Address

Researchers recently analyzed a CoreWarrior malware sample, which spreads aggressively by creating numerous copies...