Uncontrolled Search Path Vulnerability May Lead to Escalation of Privilege
CVE-2024-21814

7.3HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
16 May 2024

Summary

An escalation of privilege vulnerability exists in Intel Chipset Device Software prior to version 10.1.19444.8378. This vulnerability can be exploited by an authenticated user with local access, allowing them to gain unauthorized elevated privileges on the system. Due to the uncontrolled search path, an attacker could execute code in the context of a higher privilege level, potentially compromising the integrity and confidentiality of the system. It is crucial for users to update to the latest version to mitigate this risk. For more information, refer to Intel's security advisory.

Affected Version(s)

Intel(R) Chipset Device Software before version 10.1.19444.8378

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.