CVE-2026-2915
Received
Received - Intake
Arbitrary File Write Vulnerability in HP System Event Utility
Publication date: 2026-03-03
Last updated on: 2026-03-09
Assigner: HP Inc.
Description
Description
HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was
remediated with HP System Event Utility version 3.2.16.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hp | system_event_utility | to 3.2.16 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |