Potential Escalation of Privilege Vulnerability in Intel CSME Installer Software
CVE-2023-28389
6.7MEDIUM
What is CVE-2023-28389?
A security vulnerability exists in Intel CSME installer software versions prior to 2328.5.5.0 due to incorrect default permissions. This flaw allows an authenticated user to potentially escalate privileges through local access. If exploited, it could grant unauthorized access to sensitive system resources, thereby undermining the security posture of affected systems. Users are advised to update to the latest version to mitigate the risk associated with this vulnerability. For additional information, please refer to Intel's advisory.
Affected Version(s)
Intel(R) CSME installer software before version 2328.5.5.0