First published: Thu Dec 29 2016(Updated: )
HP ThinPro 4.4 through 6.1 mishandles the keyboard layout control panel and virtual keyboard application, which allows local users to bypass intended access restrictions and gain privileges via unspecified vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thin | =4.4 | |
Thin | =5.0 | |
Thin | =5.1 | |
Thin | =5.2 | |
Thin | =5.2.1 | |
Thin | =6.0 | |
Thin | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2246 allows local users to bypass intended access restrictions, potentially leading to unauthorized privilege escalation.
HP ThinPro versions 4.4 through 6.1 are affected by CVE-2016-2246.
To mitigate CVE-2016-2246, ensure to apply the latest security patches or updates provided by HP for the affected ThinPro versions.
No, CVE-2016-2246 is a local vulnerability that requires physical access to exploit.
CVE-2016-2246 has been classified with a medium severity level.