Potential Escalation of Privilege via Local Access in Intel XTU Software
CVE-2023-28407

7.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 February 2024

Summary

An issue exists in the Intel Extreme Tuning Utility (XTU) software that allows an authenticated user to exploit an uncontrolled search path vulnerability. This can lead to privilege escalation with local access, potentially enabling unauthorized access to system resources, configurations, or sensitive data. Users of affected versions should take note of the risk and consider applying available patches or mitigations to safeguard their systems.

Affected Version(s)

Intel(R) XTU software before version 7.12.0.29

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.