HP Touchpoint Analytics LPE Vulnerability Affects Most HP PCs

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Feb 4, 2016
2,516
15,625
3,578
53
Germany / Poland
HP patched a vulnerability discovered in the HP Touchpoint Analytics software installed by default on most HP computers running Windows, a flaw allowing attackers to escalate privileges and execute arbitrary code using SYSTEM privileges.

HP TouchPoint Analytics is a software that comes pre-installed on most HP computers in the form of a Windows service running with top-level 'NT AUTHORITY\SYSTEM' permissions and designed to collect hardware performance diagnostic info anonymously.

The local privilege escalation (LPE) vulnerability tracked as CVE-2019-6333 was found in the Open Hardware Monitor library used by HP's monitoring software.
 
HP Touchpoint Analytics Opens PCs to Code Execution Attack
The vulnerability stems from an issue with DLL loading in Open Source Hardware, used by tens of millions of computers, researchers say.
A security flaw, discovered in an open-source software program that is a key component of HP’s TouchPoint Analytics service, is opening up a wide swath of HP computers to attack. The vulnerability, if exploited by local attackers with administrative privileges, can allow them to execute arbitrary code on victim systems.
The affected software, Open Hardware Monitor, monitors temperature sensors, fan speeds, voltages, load and clock speeds of a computer. It is utilized by tens of millions of computers and is a key third-party component of HP Touchpoint Analytics, said researchers with SafeBreach Labs, who discovered the flaw.
HP TouchPoint Analytics is a service that anonymously collects diagnostic information about hardware performance. The service is pre-installed on most HP PCs, meaning the flaw has a wide attack surface, said researchers.