Uncontrolled Search Path in Intel OFU Software
CVE-2023-29161

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 November 2023

Summary

An uncontrolled search path vulnerability exists in certain versions of Intel OFU software prior to version 14.1.31. This flaw may permit an authenticated user to exploit local access, potentially enabling privilege escalation. Ensuring updated software is crucial to mitigating this risk and protecting system integrity.

Affected Version(s)

Intel(R) OFU software before version 14.1.31

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.