CVE-2022-38396
HIGHHP Factory Preinstalled Images - Privilege Escalation
Title source: llmDescription
HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This potential vulnerability was remediated starting with Windows 10 versions 21H2 on October 31, 2021.
References (1)
Core 1
Core References
Vendor Advisory
https://support.hp.com/ie-en/document/ish_7620368-7620413-16
Scores
CVSS v3
7.8
EPSS
0.0041
EPSS Percentile
33.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
Status
published
Products (10)
microsoft/windows_10_1507
microsoft/windows_10_1511
microsoft/windows_10_1607
microsoft/windows_10_1703
microsoft/windows_10_1709
microsoft/windows_10_1803
microsoft/windows_10_1809
microsoft/windows_10_1909
microsoft/windows_10_2004
microsoft/windows_10_20h2
Published
Feb 12, 2023
Tracked Since
Feb 18, 2026