HP
HP Support Assistant: vulnerabilities and CVEs
HP Support Assistant has 21 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs21
Last 12 months2
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19915 | High (7.3) | 0.11% | — | Sep 22, 2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient… |
| CVE-2026-15431 | High (7.3) | 0.09% | — | Sep 3, 2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient… |
| CVE-2025-10578 | Medium (5.8) | 0.12% | — | Oct 1, 2025 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file… |
| CVE-2025-43019 | Medium (5.8) | 0.12% | — | Jul 8, 2025 | A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion. |
| CVE-2025-43026 | High (7.1) | 0.13% | — | Jun 5, 2025 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file… |
| CVE-2022-23455 | High (7.8) | 0.19% | — | Feb 1, 2023 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and… |
| CVE-2022-23454 | High (7.8) | 0.19% | — | Feb 1, 2023 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and… |
| CVE-2022-23453 | High (7.8) | 0.19% | — | Feb 1, 2023 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and… |
| CVE-2022-38395 | High (7.8) | 2.8% | — | Dec 12, 2022 | HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and… |
| CVE-2020-6922 | High (7.8) | 0.86% | — | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. |
| CVE-2020-6921 | High (7.8) | 0.86% | — | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. |
| CVE-2020-6920 | Medium (5.5) | 0.86% | — | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. |
| CVE-2020-6919 | High (7.8) | 0.86% | — | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. |
| CVE-2020-6918 | High (7.8) | 0.86% | — | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. |
| CVE-2020-6917 | High (7.8) | 0.86% | — | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. |
| CVE-2022-23456 | Medium (5.5) | 0.28% | — | Jan 28, 2022 | Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software. |
| CVE-2019-6329 | High (7.8) | 1.6% | — | Jun 25, 2019 | HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328. |
| CVE-2019-6328 | High (7.8) | 0.73% | — | Jun 25, 2019 | HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329. |
| CVE-2018-5927 | High (7.3) | 0.38% | — | Mar 27, 2019 | HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code. |
| CVE-2017-2744 | Medium (5.5) | 0.47% | — | Jan 23, 2018 | The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1. |
| CVE-2016-2245 | Critical (9.8) | 5.9% | — | Mar 19, 2016 | HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.