A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system service.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
https://support.hp.com/us-en/document/c06559359 | vendor advisory |
http://seclists.org/fulldisclosure/2020/Feb/8 | mailing list third party advisory exploit |