Privilege Escalation Vulnerability in Intel NUC M15 Laptop Kit Keyboard LED Service Driver
CVE-2021-33095

7.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
17 November 2021

Summary

A vulnerability exists in the Intel NUC M15 Laptop Kit Keyboard LED Service driver that is due to an unquoted search path in its installer. This flaw could potentially allow an authenticated user to escalate their privileges through local access, enabling unauthorized modifications to the system. Users of affected versions should take immediate action to update the driver to the latest version to prevent exploitation.

Affected Version(s)

Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.