« Back to list

HP

HP Support Assistant: vulnerabilities and CVEs

HP Support Assistant has 21 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs21
Last 12 months2
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-19915High (7.3)0.11%—Sep 22, 2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient…
CVE-2026-15431High (7.3)0.09%—Sep 3, 2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient…
CVE-2025-10578Medium (5.8)0.12%—Oct 1, 2025
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file…
CVE-2025-43019Medium (5.8)0.12%—Jul 8, 2025
A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion.
CVE-2025-43026High (7.1)0.13%—Jun 5, 2025
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file…
CVE-2022-23455High (7.8)0.19%—Feb 1, 2023
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and…
CVE-2022-23454High (7.8)0.19%—Feb 1, 2023
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and…
CVE-2022-23453High (7.8)0.19%—Feb 1, 2023
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and…
CVE-2022-38395High (7.8)2.8%—Dec 12, 2022
HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and…
CVE-2020-6922High (7.8)0.86%—Feb 16, 2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
CVE-2020-6921High (7.8)0.86%—Feb 16, 2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
CVE-2020-6920Medium (5.5)0.86%—Feb 16, 2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
CVE-2020-6919High (7.8)0.86%—Feb 16, 2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
CVE-2020-6918High (7.8)0.86%—Feb 16, 2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
CVE-2020-6917High (7.8)0.86%—Feb 16, 2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
CVE-2022-23456Medium (5.5)0.28%—Jan 28, 2022
Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.
CVE-2019-6329High (7.8)1.6%—Jun 25, 2019
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.
CVE-2019-6328High (7.8)0.73%—Jun 25, 2019
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.
CVE-2018-5927High (7.3)0.38%—Mar 27, 2019
HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.
CVE-2017-2744Medium (5.5)0.47%—Jan 23, 2018
The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1.
CVE-2016-2245Critical (9.8)5.9%—Mar 19, 2016
HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation2
  2. T1548 Abuse Elevation Control Mechanism1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by HP