Insecure Inherited Permissions in Intel Server Configuration Utility
CVE-2023-34997
6.7MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 November 2023
Summary
The installer for Intel Server Configuration Utility software prior to version 16.0.9 is susceptible to an issue related to insecure inherited permissions. This flaw could allow an authenticated user with local access to exploit these permissions, potentially leading to elevation of privileges. Remediation involves updating the software to the latest version to mitigate this risk.
Affected Version(s)
Intel Server Configuration Utility software before version 16.0.9
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved