CVE-2025-13492
A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerability could potentially allow a local attacker to escalate privileges via a race condition when installing packages.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.08%
- CWE
- CWE-363
- Published
- 2025-12-03
- Last modified
- 2026-03-13
Affected products
- HP Inc HP Image Assistant
Weakness type
Related vulnerabilities
- CVE-2025-52881 — runc: LSM labels can be bypassed with malicious config using dummy procfs files
- CVE-2025-52565 — container escape due to /dev/console mount and related races
- CVE-2025-31133 — runc container escape via "masked path" abuse due to mount race conditions
- CVE-2025-62596 — youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects
- CVE-2025-62161 — youki container escape via "masked path" abuse due to mount race conditions
- CVE-2024-45310 — runc can be confused to create empty files/directories on the host
- CVE-2024-27102 — Improper isolation of server file access in github.com/pterodactyl/wings
- CVE-2022-21658 — Race condition in std::fs::remove_dir_all in rustlang