Insecure Inherited Permissions in Intel Server Configuration Utility
CVE-2023-34997

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 November 2023

Summary

The installer for Intel Server Configuration Utility software prior to version 16.0.9 is susceptible to an issue related to insecure inherited permissions. This flaw could allow an authenticated user with local access to exploit these permissions, potentially leading to elevation of privileges. Remediation involves updating the software to the latest version to mitigate this risk.

Affected Version(s)

Intel Server Configuration Utility software before version 16.0.9

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.