Escalation of Privilege Vulnerability in Intel NUC Kits HDMI Firmware Update Tool
CVE-2023-32658
6.7MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 November 2023
Summary
The Intel NUC Kits NUC7i3DN, NUC7i5DN, and NUC7i7DN HDMI firmware update tool contains an unquoted search path vulnerability that could allow authenticated users local access to escalate their privileges. This flaw affects versions prior to 1.79.1.1 and poses a significant risk for users who may inadvertently run applications with elevated permissions. Proper remediation measures and updates to the firmware are essential to protect against potential exploits.
Affected Version(s)
Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved