A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerability could potentially allow a local attacker to escalate privileges via a race condition when installing packages.
The product checks the status of a file or directory before accessing it, which produces a race condition in which the file can be replaced with a link before the access is performed, causing the product to access the wrong file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Image_assistant | Hp | * | 5.3.3 (excluding) |