vendor:
HP System Event Utility
by:
hyp3rlinx
7.8
CVSS
HIGH
Local Privilege Escalation
CWE
Product Name: HP System Event Utility
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2019-18915
CPE:
Platforms Tested:
2020
HP System Event Utility – Local Privilege Escalation
The HP System Event service "HPMSGSVC.exe" will load an arbitrary EXE and execute it with SYSTEM integrity. HPMSGSVC.exe runs a background process that delivers push notifications. The problem is that HP Message Service will load and execute any arbitrary executable named "Program.exe" if found in the users c: drive. This results in arbitrary code execution persistence mechanism if an attacker can place an EXE in this location and can be used to escalate privileges from Admin to SYSTEM.
Mitigation:
HP has/is released/releasing a mitigation: https://support.hp.com/us-en/document/c06559359