Improper Access Control in Intel OFU Software Kernel Mode Driver
CVE-2022-41784
8.8HIGH
Summary
An improper access control vulnerability exists in the kernel mode driver for Intel OFU software prior to version 14.1.30. An authenticated user with local access may exploit this issue to escalate privileges, potentially gaining unauthorized access to resources and executing arbitrary code with elevated privileges, leading to a compromise of system integrity. It is crucial for users to update their Intel OFU software to the latest version to mitigate this risk.
Affected Version(s)
Intel(R) OFU software before version 14.1.30
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved