Improper Access Control in Intel's oneAPI Toolkit and Component Software Installers
CVE-2023-27391
6.7MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 11 August 2023
Summary
The vulnerability arises from improper access control mechanisms within Intel's oneAPI Toolkit and related component software installers prior to version 4.3.1.493. This flaw could allow a privileged user to leverage local access to potentially escalate their privileges improperly, leading to unauthorized actions within the system. Organizations using affected versions should review their security postures and apply necessary updates to mitigate risks.
Affected Version(s)
Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved