Potential Escalation of Privilege via Local Access in Intel Media SDK and oneVPL Software
CVE-2023-22656

3.9LOW

Key Information:

Vendor
Intel
Vendor
CVE Published:
16 May 2024

Summary

The identified vulnerability allows authenticated users to exploit an out-of-bounds read issue in Intel's Media SDK and certain versions of oneVPL software. This vulnerability may lead to potential escalation of privileges through local access, allowing attackers to manipulate system security and access sensitive information. Users of Intel Media SDK and oneVPL software are advised to update to the latest versions to mitigate potential risks associated with this security flaw.

Affected Version(s)

Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.