Uncontrolled Search Path Vulnerability in Intel oneAPI Toolkit
CVE-2023-28823

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
11 August 2023

Summary

An uncontrolled search path vulnerability exists in some versions of the Intel oneAPI Toolkit and its software component installers. This issue may allow authenticated users with local access to potentially escalate their privileges. Proper checks and balances in the installation process are necessary to mitigate this risk. For further details and mitigation strategies, refer to the advisory provided by Intel.

Affected Version(s)

Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.