Improper Access Control in Intel's oneAPI Toolkit and Component Software Installers
CVE-2023-27391

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
11 August 2023

Summary

The vulnerability arises from improper access control mechanisms within Intel's oneAPI Toolkit and related component software installers prior to version 4.3.1.493. This flaw could allow a privileged user to leverage local access to potentially escalate their privileges improperly, leading to unauthorized actions within the system. Organizations using affected versions should review their security postures and apply necessary updates to mitigate risks.

Affected Version(s)

Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.