8.8
CVE-2024-27458
- EPSS 0.06%
- Veröffentlicht 07.10.2024 17:15:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle hp-security-alert@hp.com
- CVE-Watchlists
- Unerledigt
HP Hotkey Support – Escalation of Privilege
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerhp
≫
Produkt
elite_dragonfly_max_firmware
Default Statusunknown
Version
8.10.42.190
Version <
8.10.42.190_rev1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.193 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| hp-security-alert@hp.com | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.