Uncontrolled Search Path Vulnerability in Intel RSTe Software RAID Driver
CVE-2020-8687
7.8HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 13 August 2020
Summary
The installer for Intel RSTe Software RAID Driver on Intel Server Board M10JNP2SB contains an uncontrolled search path vulnerability, which may permit an authenticated user to exploit local access to potentially escalate privileges. This vulnerability is present in all versions prior to 4.7.0.1119, emphasizing the importance of updating software to mitigate security risks associated with user privileges.
Affected Version(s)
Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB Advisory Before version 4.7.0.1119
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved