AI description
CVE-2026-12555 is a privilege escalation vulnerability found in HP Easy Start for macOS, affecting versions prior to 2.16.7.260722. This flaw, categorized under CWE-379 (Creation of Temporary File in Directory with Insecure Permissions), stems from the HP Easy Start Uninstaller component utilizing predictable, world-writable paths for temporary files while operating with administrative privileges. A local attacker can exploit this by creating symbolic links at these insecure temporary file locations before the privileged process starts. When the uninstaller accesses these paths, it may follow the attacker-controlled symlink, leading to privileged file modification or corruption, such as appending application-generated log data to an attacker-chosen target. HP has released updated software to address this issue.
- Description
- Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
- Source
- hp-security-alert@hp.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 7.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- hp-security-alert@hp.com
- CWE-379
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
10
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) https://t.co/LcYlOVgrv5
@Dinosn
3 Sept 2026
4900 Impressions
3 Retweets
8 Likes
5 Bookmarks
0 Replies
0 Quotes
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) https://t.co/YIBPkl86LR
@_r_netsec
2 Sept 2026
1056 Impressions
1 Retweet
3 Likes
2 Bookmarks
0 Replies
0 Quotes