Escalation of Privilege in Intel NUC Kit Thunderbolt 3 Firmware Update Tool
CVE-2023-32660

6.7MEDIUM

What is CVE-2023-32660?

The Thunderbolt 3 Firmware Update Tool for Intel NUC Kit NUC6i7KYK before version 46 contains a flaw that allows authenticated users to modify the environment search path. This vulnerability can potentially enable attackers with local access to escalate their privileges on the system, leading to unauthorized actions. It is crucial for users to upgrade to the latest version of the tool to mitigate this risk effectively.

Affected Version(s)

Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-32660 : Escalation of Privilege in Intel NUC Kit Thunderbolt 3 Firmware Update Tool