ZeroHour

CVE-2026-15431

mass

Local Privilege Escalation in HP Support Assistant (CVE-2026-15431)

CVSS 4.0
7.3 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-15431 is a local privilege escalation flaw in HP Support Assistant, HP's preinstalled PC support and maintenance agent, caused by insufficient access controls (CWE-1220) in versions prior to 9.53.2.0. An attacker who already has low-privileged local access to a PC running the vulnerable agent can trigger the flaw without user interaction, gaining elevated access to the system (the CVSS 4.0 vector rates the impact on confidentiality, integrity, and availability of the vulnerable system as high). Successful exploitation would let the attacker run code with elevated rights, enabling full control and persistence on the affected machine. Any HP consumer or business Windows PC with HP Support Assistant older than 9.53.2.0 is affected. There is currently no public proof-of-concept, no CISA KEV listing, and a very low EPSS score (0.1%), indicating no known exploitation.

What to do: Update HP Support Assistant to version 9.53.2.0 or later, using the agent's built-in update function or HP's support site, and verify the installed version on each managed PC. Because exploitation requires local access, prioritize shared or multi-user machines and systems where untrusted users hold local accounts. No workaround or alternative mitigation is described in the advisory data.

Affected
HP Support AssistantAll versions prior to 9.53.2.0
Estimated exposure
masstens of millions of HP Windows PCs (the agent is preloaded on most HP consumer and business machines) — HP accounts for roughly one-fifth of global PC shipments (tens of millions of units per year) and ships Support Assistant preinstalled on the large majority of those Windows PCs, implying an installed base well above one million devices;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

Weakness
CWE-1220
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.