Potential Escalation of Privilege via Local Access in Previous Versions of Intel GPA Software
CVE-2023-43629

7.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
16 May 2024

Summary

An issue has been identified in the installers for Intel Graphics Performance Analyzers (GPA), where incorrect default permissions may enable an authenticated user to escalate their privileges via local access. This vulnerability affects versions of the software prior to 2023.3. It is crucial for users to ensure that their installations are updated to the latest version to mitigate any potential risks associated with this flaw.

Affected Version(s)

Intel(R) GPA software installers before version 2023.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.