Privilege Escalation Vulnerability in Intel NUC M15 Laptop Kit Keyboard LED Service Driver
CVE-2021-33095
7.8HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 17 November 2021
Summary
A vulnerability exists in the Intel NUC M15 Laptop Kit Keyboard LED Service driver that is due to an unquoted search path in its installer. This flaw could potentially allow an authenticated user to escalate their privileges through local access, enabling unauthorized modifications to the system. Users of affected versions should take immediate action to update the driver to the latest version to prevent exploitation.
Affected Version(s)
Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved