CVE-2024-27458
Last modified
CVE-2024-27458 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-27458?
How severe is CVE-2024-27458?
How do I fix CVE-2024-27458?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-2745Rapid7's InsightVM maintenance mode login page suffers from …3.3
- CVE-2024-27453In Extreme XOS through 22.6.1.4, a read-only user can escala…8.6
- CVE-2024-27454orjson.loads in orjson before 3.9.15 does not limit recursio…7.5
- CVE-2024-27455In the Bentley ALIM Web application, certain configuration s…9.1
- CVE-2024-27456rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissi…9.1
- CVE-2024-27457Improper check for unusual or exceptional conditions in Inte…2.5
- CVE-2024-27459The interactive service in OpenVPN 2.6.9 and earlier allows …7.8
- CVE-2024-2746Incomplete fix for CVE-2024-1929 The problem with CVE-2024-…8.8
- CVE-2024-27460A privilege escalation exists in the updater for Plantronics…6.7
- CVE-2024-27461Incorrect default permissions in software installer for Inte…5.5
- CVE-2024-27462Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2024-2747CWE-428: Unquoted search path or element vulnerability exist…7.8
Are you affected by CVE-2024-27458?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
