Potential Escalation of Privilege Vulnerability in Intel CSME Installer Software
CVE-2023-32633

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 March 2024

Summary

A vulnerability exists in Intel CSME installer software prior to version 2328.5.5.0 due to improper input validation. This flaw may allow an authenticated user to exploit the issue and potentially escalate privileges through local access. System administrators and users should review affected versions and consider applying necessary updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Intel(R) CSME installer software before version 2328.5.5.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.