Uncontrolled Search Path Vulnerability in Intel oneAPI Toolkit Software Installers
CVE-2023-22355

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
10 May 2023

Summary

A vulnerability exists in certain installers for Intel oneAPI Toolkit and component software versions before 4.3.0.251 due to an uncontrolled search path issue. This flaw allows an authenticated user local access that could potentially facilitate the escalation of privileges, harming system integrity and security. Affected users should seek to upgrade to the latest version to mitigate this risk.

Affected Version(s)

Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.