Unauthenticated Remote Access Privilege Escalation Vulnerability in Intel Neural Compressor Software
CVE-2024-22476

10CRITICAL

Key Information:

Vendor
Intel
Vendor
CVE Published:
16 May 2024

Badges

🟣 EPSS 48%📰 News Worthy

Summary

The vulnerability arises from improper input validation in Intel Neural Compressor software, prior to version 2.5.0, which may allow unauthenticated users to potentially exploit the system. This flaw could enable unauthorized remote access, leading to escalated privileges within the affected software environment. Users are strongly advised to update to the latest version to mitigate this risk.

Affected Version(s)

Intel(R) Neural Compressor software before version 2.5.0

Get notified when SecurityVulnerability.io launches alerting 🔔

News Articles

Intel Discloses Max Severity Bug in Its AI Model Compression Software

The improper input validation issue in Intel Neural Compressor enables remote attackers to execute arbitrary code on affected systems.

References

EPSS Score

48% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 📰

    First article discovered

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.