-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Notebooks
- Notebook Hardware and Upgrade Questions
- Security Bulletin - Jan 30 2108

Create an account on the HP Community to personalize your profile and ask a question
02-08-2018 01:36 PM
I received the following email. The links are very cryptic. Is this a Phishing email or is it real? This submission form removed invalid HTML before it would post it.
Critical Security Bulletin - Jan 30 2018
Products: Laptops and Hybrids, Desktops & Workstations, Point of Sale Systems, Tablets
Description: HPSBHF03578 rev. 1 - Intel Graphics Driver - Pointer Dereference / Type Confusion in HECI Service
Solved! Go to Solution.
Accepted Solutions
02-10-2018 10:14 AM
Hi @Bill_1944,
Welcome to HP Forums,
This is a great place to get support, find answers and tips,
Thank you for posting your query, I'll be more than glad to help you out 🙂
As I understand, you're in need of support.
Don't worry as I'll be glad to help,
This is a genuine email you've received and it is the authentic website. This is the VULNERABILITY. You could refer to the summary:
CVE-2017-5717: The Intel® Content Protection HECI Service has a Type Confusion vulnerability which potentially can lead to a privilege escalation. The HECI service software is distributed as part of the Intel Graphics Driver and is used by the graphics driver to provide premium content playback services.
CVE-2017-5727: The Intel® Graphics Drivers for Windows Code can fail to adequately validate a pointer input. This may lead to modification of kernel memory and a potential for an escalation of privilege.
You need to check if your computer is listed in the list of all the computers.
If it is not listed, you could ignore the email.
If your model name is listed in the article, then HP is working to update the affected systems. Schedules for these updates will be provided via this bulletin. Impacted HP products are shown in the table below. We will update the table as softpaqs become available. Check back frequently for updates.
Hope this helps!
Have a great day 🙂
Cheers!
02-10-2018 10:14 AM
Hi @Bill_1944,
Welcome to HP Forums,
This is a great place to get support, find answers and tips,
Thank you for posting your query, I'll be more than glad to help you out 🙂
As I understand, you're in need of support.
Don't worry as I'll be glad to help,
This is a genuine email you've received and it is the authentic website. This is the VULNERABILITY. You could refer to the summary:
CVE-2017-5717: The Intel® Content Protection HECI Service has a Type Confusion vulnerability which potentially can lead to a privilege escalation. The HECI service software is distributed as part of the Intel Graphics Driver and is used by the graphics driver to provide premium content playback services.
CVE-2017-5727: The Intel® Graphics Drivers for Windows Code can fail to adequately validate a pointer input. This may lead to modification of kernel memory and a potential for an escalation of privilege.
You need to check if your computer is listed in the list of all the computers.
If it is not listed, you could ignore the email.
If your model name is listed in the article, then HP is working to update the affected systems. Schedules for these updates will be provided via this bulletin. Impacted HP products are shown in the table below. We will update the table as softpaqs become available. Check back frequently for updates.
Hope this helps!
Have a great day 🙂
Cheers!