Vulnerability Description
HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Fusion | < 1.38.2601.0 |
| Hp | Support Assistant | < 9.11 |
Related Weaknesses (CWE)
References
- https://support.hp.com/us-en/document/ish_6788123-6788147-16/hpsbhf03809Vendor Advisory
- https://support.hp.com/us-en/document/ish_6788123-6788147-16/hpsbhf03809Vendor Advisory
FAQ
What is CVE-2022-38395?
CVE-2022-38395 is a vulnerability with a CVSS score of 7.8 (HIGH). HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vu...
How severe is CVE-2022-38395?
CVE-2022-38395 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38395?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Fusion, Hp Support Assistant.