• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Serious Flaw Found in HP OMEN Driver

You are here: Home / General Cyber Security News / Serious Flaw Found in HP OMEN Driver
September 15, 2021

A significant flaw has been uncovered in the driver of a well-known Laptop gaming software program utilised by thousands and thousands. 

Researchers from SentinelLabs published details of the vulnerability in the HP Omen Gaming Hub on September 14. They mentioned that attackers could exploit the flaw to regionally escalate to kernel-mode privileges.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“With this stage of obtain, attackers can disable security solutions, overwrite process elements, corrupt the OS, or execute any malicious functions unimpeded,” wrote researchers. 

Omen will come preinstalled on all HP OMEN desktops and laptops and can be applied to command and improve options such as gadget GPU, admirer speeds, CPU overclocking, memory and much more. 

The vulnerability was reported to HP on February 17, 2021, and was afterwards provided a Widespread Vulnerability Scoring Program (CVSS) rating of 7.8, making it a large-severity flaw. 

No proof of the flaw’s currently being exploited in the wild was uncovered by SentinelOne. 

“While we have not seen any indicators that these vulnerabilities have been exploited in the wild up until now, using any OMEN-branded Pc with the vulnerable driver used by OMEN Gaming Hub makes the user possibly susceptible,” pointed out researchers. “Therefore, we urge people of OMEN PCs to assure they choose correct mitigating actions with out delay.”

Commenting on the freshly unearthed flaw, Jamie Boote, security specialist at the Synopsys Computer software Integrity Team, claimed, “With the rise of remote staff during the Covid-19 Pandemic, the collision among company IT environments and personalized hardware will only rise as employees offer extra of their have components to continue on to customise and equip their house workplaces. 

“It is difficult to foresee all probable driver and hardware vulnerabilities that can arise from these cases, so it is critical for IT departments to acknowledge and respond to threats these types of as these when they’re built general public.”

Boote extra that the enforcement of proactive security actions these kinds of as retaining up with danger intelligence feeds, restricting software installations to only accredited software program sources and preserving approved workstation photos can limit the effects of threats this sort of as this gaming hub privilege escalation bug. 

“Perhaps this vulnerability is a reminder of why it is termed ‘The Bleeding Edge,’” said Boote.


Some components of this posting are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Americans Fined After Hacking for Foreign Government
Next Post: Arizona Medical Practice Permanently Loses EHR Data Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.