ZeroHour

CVE-2026-82346

mass

Local Privilege Escalation in HP ImageDiags before 5.0.0.36

CVSS 4.0
7.0 high
EPSS
<1%p1
Published
()
Modified
AI analysis

HP ImageDiags, a diagnostics utility distributed by HP for its Windows-based commercial PCs, is affected by a local privilege escalation vulnerability in versions prior to 5.0.0.36. HP attributes the flaw to insufficient access controls, and the CWE-379 mapping points to creation of temporary files with insecure permissions as the likely mechanism. The CVSS 4.0 vector confirms a local attack requiring only low privileges (with active user interaction), and successful exploitation yields high impact on the confidentiality, integrity, and availability of the affected machine — effectively granting the attacker elevated control of that system. Only HP endpoints with ImageDiags installed, typically enterprise-managed commercial PCs, are affected. There is no known exploitation: the issue is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.

What to do: Inventory Windows endpoints for HP ImageDiags and update to version 5.0.0.36 or later per HP's security advisory. Until patched, limit use of the tool on shared or multi-user workstations and treat unprivileged local code execution on those hosts as elevated risk. No exploitation is currently known, so remediation through normal patch cycles is reasonable.

Affected
HP ImageDiagsAll versions prior to 5.0.0.36
Estimated exposure
masswell over 100,000 installations, plausibly on the order of 1M+ HP commercial endpoints (estimate; no public install counts) — HP is one of the world's largest PC vendors and ImageDiags is part of the diagnostics software deployed with HP commercial Windows PCs, so even a fraction of HP's tens of millions of annual commercial shipments carrying the tool puts the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

Weakness
CWE-379
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.