Local Access Escalation Vulnerability in Intel Unite Client for Windows
CVE-2021-0112

7.3HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
9 June 2021

Summary

The Intel Unite Client for Windows prior to version 4.2.25031 contains a vulnerability due to the use of an unquoted service path. This flaw may allow an authenticated user to escalate privileges, leveraging local access to execute malicious actions. Proper configuration and sanitization of service paths are crucial to mitigating this vulnerability.

Affected Version(s)

Intel Unite(R) Client for Windows before version 4.2.25031

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.