vendor:
HP Software Update
by:
7.5
CVSS
HIGH
Arbitrary File Write Access
CWE
Product Name: HP Software Update
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Remotely Exploitable Flaw in HP Notebook Software Update Tool
The flaw is located in the HP Software Update tool, which is preinstalled in HP notebook machines. It allows a potential attacker to remotely write arbitrary files on the system, leading to user files loss or damage to vital system files, potentially rendering the PC unbootable.
Mitigation:
Update to the latest version of the HP Software Update tool or uninstall it completely. Avoid clicking on suspicious links.