Null Pointer Dereference in Intel VROC Software
CVE-2022-29508

6.3MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
10 May 2023

Summary

A null pointer dereference vulnerability in Intel VROC software can potentially allow an authenticated user to escalate privileges through local access. This flaw exists in versions prior to 7.7.6.1003, leaving systems susceptible to unauthorized access and manipulation of sensitive configurations. Users are encouraged to update to the latest version to mitigate this risk.

Affected Version(s)

Intel(R) VROC software before version 7.7.6.1003

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.