Escalation of Privilege in Intel Thunderbolt DCH Drivers for Windows
CVE-2023-24542

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 February 2024

Summary

The vulnerability allows an authenticated user to potentially escalate privileges due to an unquoted search path within specific versions of the Intel Thunderbolt DCH drivers for Windows. This flaw could be exploited by local, authenticated users, potentially leading to unauthorized system access and compromise. Timely updates and adherence to security recommendations are essential to mitigate the risk associated with this vulnerability. For detailed information and guidance, refer to the official advisory from Intel.

Affected Version(s)

Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.