SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-2209

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to…

MEDIUM 6.3EPSS 0.21%

Does this matter?

Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.

Description

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
EPSS
0.21% probability · 11th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
hp/26k70b firmware · hp/297x1a firmware · hp/2a9q5a firmware · hp/26k72a firmware · hp/26k69a firmware · hp/26k70a firmware · hp/26k71a firmware · hp/26k68a firmware · hp/26k67a firmware · hp/3xv19a firmware · hp/7fr52a firmware · hp/7fr57a firmware · hp/7fr53a firmware · hp/7fr58a firmware · hp/7fr61a firmware · hp/5ar83a firmware · hp/5ar84a firmware · hp/5ar85a firmware · hp/8rk11a firmware · hp/3xv17a firmware · +8 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.