HomeSecurityMillions of HP OMEN PCs are affected by a serious vulnerability

Millions of HP OMEN PCs are affected by a serious vulnerability

Millions of HP OMEN gaming PCs are exposed to attacks from a high-severity vulnerability that could allow threat actors to cause a denial of service or escalate privileges and disable security solutions.

HP OMEN

See also: Microsoft has fixed a vulnerability in Azure Container Instances

The security flaw (identified as CVE-2021-3437) was found in a driver used by the OMEN Gaming Hub software that comes pre-installed on all HP OMEN desktops and laptops.

CVE-2021-3437 is due to HP's choice to use vulnerable code partially copied from WinRing0.sys, an open source driver, to create the HpPortIox64.sys driver that the OMEN Gaming Hub software uses to read/write core memory, PCI configurations, IO ports, and Model-Specific Registers (MSRs).

The full list of vulnerable devices is available here and includes OMEN and HP Pavilion gaming laptops, as well as HP ENVY, HP Pavilion and OMEN gaming desktops.

See also: New DNS vulnerability allows for 'state-level espionage'

Millions of devices and users were affected

The OMEN Gaming Hub can be used to enhance the gaming experience through overclocking, optimizing system settings for various game profiles, customizing lighting on gaming devices and accessories, and more.

Considering that the software can also be downloaded from the Microsoft Store and installed on any Windows 10 PC equipped with peripherals sold under HP's OMEN brand, millions of computers worldwide are affected by this flaw.

Once attackers gain SYSTEM privileges on targeted HP OMEN devices, they can easily disable security products, replace system components with malicious payloads, corrupt the underlying operating system, or perform other malicious tasks of their choosing.

The list of software products affected by this vulnerability includes:

  • HP OMEN Gaming Hub before version 11.6.3.0
  • HP OMEN Gaming Hub SDK before 1.0.44

See also: Atlassian: Update to fix a critical Jira vulnerability

Security patches available from July

HP has released patches for this high severity vulnerability through the Microsoft Store on July 27 and has published a security advisory earlier.

SentinelOne also shared its findings in today's report to warn users to update their software and defend their systems from attackers using CVE-2021-3437 exploits.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS