Lucene search

K
hpHP, HP Product Security Response Team (PSRT)HP:C06559359
HistoryFeb 07, 2020 - 12:00 a.m.

HPSBHF03650 rev. 2 - HP System Event Utility Execution of Arbitrary Code

2020-02-0700:00:00
HP, HP Product Security Response Team (PSRT)
support.hp.com
49

0.001 Low

EPSS

Percentile

25.8%

Potential Security Impact

Execution of Arbitrary Code

Source: HP, HP Product Security Response Team (PSRT)

Reported By: John Page (aka Hyp3rlinx) of ApparitionSec

VULNERABILITY SUMMARY

A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33.

This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system service.

RESOLUTION

HP is releasing software updates for notebook platforms that use HP System Event Utility. HP recommends updating HP System Event Utility to the mitigated version or later, as listed below.

Product Name

|

Updated Version

|

SoftPaq #

|

SoftPaq Link

—|—|—|—

HP System Event Utility

|

1.4.33 or later

|

SP101543

|

<https://ftp.hp.com/pub/softpaq/sp101501-102000/sp101543.exe&gt;

How to identify the version of HP System Event Utility installed.

Method 1

  1. On devices with Windows 10 operating system, right-click the Windows Start button and select Apps and Features.

  2. Navigate to HP System Event Utility. If HP System Event Utility is not in the list of installed applications, your system is not impacted.

  3. Select HP System Event Utility to view the software version information.

  4. If the version is lower than 1.4.33, then update your software to the version1.4.33 or later.

Method 2

  1. On devices with Windows operating system, in the Windows Search menu, type Control Panel.

  2. Click Control Panel.

  3. In Control Panel, click Programs and then click Uninstall a Program.

  4. On the Programs and Features screen, navigate to HP System Event Utility to view the software version information.

  5. If the version is lower than 1.4.33, then update your software to the version1.4.33 or later.

> note:
>
> HP recommends keeping your system up to date with the latest firmware and software.

0.001 Low

EPSS

Percentile

25.8%