Potential Escalation of Privilege Vulnerability in Intel CSME Installer Software
CVE-2023-28389
6.7MEDIUM
Summary
A security vulnerability exists in Intel CSME installer software versions prior to 2328.5.5.0 due to incorrect default permissions. This flaw allows an authenticated user to potentially escalate privileges through local access. If exploited, it could grant unauthorized access to sensitive system resources, thereby undermining the security posture of affected systems. Users are advised to update to the latest version to mitigate the risk associated with this vulnerability. For additional information, please refer to Intel's advisory.
Affected Version(s)
Intel(R) CSME installer software before version 2328.5.5.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved