Escalation of Privilege in Intel NUC Kit Thunderbolt 3 Firmware Update Tool
CVE-2023-32660
6.7MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 November 2023
Summary
The Thunderbolt 3 Firmware Update Tool for Intel NUC Kit NUC6i7KYK before version 46 contains a flaw that allows authenticated users to modify the environment search path. This vulnerability can potentially enable attackers with local access to escalate their privileges on the system, leading to unauthorized actions. It is crucial for users to upgrade to the latest version of the tool to mitigate this risk effectively.
Affected Version(s)
Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved