Potential Escalation of Privilege via Local Access in Previous Versions of Intel GPA Software
CVE-2023-24460

7.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
16 May 2024

Summary

Improper default permissions in Intel GPA software installers prior to version 2023.3 can be exploited by authenticated users. This flaw allows local access that may lead to privilege escalation, which can compromise system integrity and security. It highlights the critical importance of maintaining updated software and the risks associated with default configurations. Users and administrators are encouraged to review their installations and apply necessary updates to mitigate potential risks.

Affected Version(s)

Intel(R) GPA software installers before version 2023.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.