CVE-2025-10577 Details
Description
Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities
A privilege escalation vulnerability has been identified in the audio package of specific HP PC products that utilize the Sound Research SECOMN64 driver. HP is releasing updated audio packages to address this vulnerability.
The vulnerabilities have been fixed in the Sonitude Audio Effects Component Driver version 2.1.1.27 or higher. HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the vulnerabilities. Users should check the HP Customer Support - Software and Driver Downloads site for the latest update for their product model.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 15, 2025CISA-ADP
Assessed Oct 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hp.com/us-en/document/ish_13092608-13092602-16/hpsbhf04051 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HP Business Notebook PCs | All versions |
CPE
Remediation
| |
| HP Business Desktop PCs | All versions |
CPE
Remediation
| |
| HP Retail Point-of-Sale Systems | All versions |
CPE
Remediation
| |
| HP Workstations | All versions |
CPE
Remediation
| |
| HP Thin Client PCs | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 15, 2025 | New CVE Received | [email protected] |
Volerion