Escalation of Privilege Vulnerability in Intel NUC Kits HDMI Firmware Update Tool
CVE-2023-32658

6.7MEDIUM

Key Information:

Summary

The Intel NUC Kits NUC7i3DN, NUC7i5DN, and NUC7i7DN HDMI firmware update tool contains an unquoted search path vulnerability that could allow authenticated users local access to escalate their privileges. This flaw affects versions prior to 1.79.1.1 and poses a significant risk for users who may inadvertently run applications with elevated permissions. Proper remediation measures and updates to the firmware are essential to protect against potential exploits.

Affected Version(s)

Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.