Vulnerability found and fixed in HP bloatware

General News

Summary

As such, the app usually whitelisted and runs with admin rights on HP systems -- to be able to access various details from software drivers and other hardware components. But in a report shared with ZDNet this week, Peleg Hadar, a security researcher with SafeBreach Labs, said he found a way to hijack the applications normal mode of operation and load malicious DLL files to run rogue code with elevated privileges. Hadar found what security experts call a local privilege escalation (LPE), a type of vulnerability thats quite common in modern software. The vulnerability wont allow hackers to take over a system from a remote location, but it will allow local apps or malware to funnel malicious commands through its code and execute those operations with full admin rights. While most LPE vulnerabilities are low risk, this ones severity is amplified by the apps huge install-base -- being found on hundreds of millions of HP desktops and laptops.

Classifications

industries
Entertainment
applications
AI & Machine learning

AskAI Classifications

Labels
Enterprise Software SaaS IT Management Software

Linked Companies

HP
$1B+