7.8
CVSSv3

CVE-2019-18915

Published: 13/02/2020 Updated: 01/01/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local malicious user to execute arbitrary code via an HP System Event Utility system service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hp system event utility

Vendor Advisories

A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1433 This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system service ...

Exploits

The HP System Event service "HPMSGSVCexe" will load an arbitrary EXE and execute it with SYSTEM integrity HPMSGSVCexe runs a background process that delivers push notifications The problem is that the HP Message Service will load and execute any arbitrary executable named "Programexe" if it is found in the user's c:\ drive ...

Mailing Lists

[+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/HP-SYSTEM-EVENT-UTILITY-LOCAL-PRIVILEGE-ESCALATIONtxt [+] twittercom/hyp3rlinx [+] ISR: ApparitionSec [Vendor] wwwhpcom [Product] HP System Event Utility The genuine HPMSGSVCexe file is a software component ...