{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-106177", "assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2", "state": "PUBLISHED", "assignerShortName": "hp", "dateReserved": "2026-10-06T16:28:52.187Z", "datePublished": "2026-10-08T15:32:16.010Z", "dateUpdated": "2026-10-09T03:55:52.322Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2", "shortName": "hp", "dateUpdated": "2026-10-08T16:00:38.312Z" }, "title": "HP Sure Click Kernel Buffer Overflow", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-122", "description": "CWE-122: Heap-based Buffer Overflow", "type": "CWE" } ] } ], "affected": [ { "vendor": "HP Inc", "product": "HP Sure Click Enterprise", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "4.4.33", "versionType": "custom" } ], "defaultStatus": "unaffected" }, { "vendor": "HP Inc", "product": "HP Wolf Security for Business", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "4.4.33", "versionType": "custom" } ], "defaultStatus": "unaffected" }, { "vendor": "HP Inc", "product": "HP Wolf Pro Security", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "4.4.33", "versionType": "custom" } ], "defaultStatus": "unaffected" }, { "vendor": "HP Inc", "product": "HP Wolf Pro Security Edition", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "4.4.33", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.
" } ] } ], "references": [ { "url": "https://support.hp.com/us-en/document/ish_15759419-15759442-16/hpsbhf04157" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseSeverity": "MEDIUM", "baseScore": 6.4, "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } } ], "credits": [ { "lang": "en", "value": "Julian Horoszkiewicz (Atos Threat Research Center)", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.5" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-08T00:00:00+00:00", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3", "id": "CVE-2026-106177" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-09T03:55:52.322Z" } } ] } }