Three HP Easy Start Flaws Let Attackers Gain Root Privileges on macOS
ID: cae874cc-9b24-57bc-a545-855ca8d5e908
STIX ID: report--cae874cc-9b24-57bc-a545-855ca8d5e908
Feed Name: GBHackers
Three high-severity vulnerabilities were discovered in HP Easy Start for macOS affecting the uninstaller's predictable temporary-file usage (allowing privileged file modification via symlink), an unmaintained embedded OSPFTP download component that can fall back to FTP (exposing package downloads), and an App Transport Security configuration that permits cleartext HTTP. Combined, these issues could allow local unprivileged users to cause root-owned file corruption or denial-of-service and could enable network-positioned attackers to intercept or manipulate installer packages under fallback conditions; HP patched the issues in HP Easy Start 2.16.7.260722 and recommends updating and removing outdated installers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
