Unquoted Search Path Vulnerability in Intel Server Firmware Update Utility
CVE-2023-22841
6.7MEDIUM
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 11 August 2023
What is CVE-2023-22841?
The software installer for the System Firmware Update Utility (SysFwUpdt) on certain Intel Server Boards and Intel Server Systems, specifically those based on the Intel 621A Chipset and versions preceding 16.0.7, contains an unquoted search path vulnerability. This flaw may allow an authenticated user to leverage local access to potentially escalate their privileges, posing a security risk to the affected systems.
Affected Version(s)
System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server Systems Based on Intel(R) 621A Chipset before version 16.0.7