Uncontrolled Search Path Vulnerability in Intel High Level Synthesis Compiler
CVE-2024-23907
7.8HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 August 2024
Summary
An uncontrolled search path vulnerability exists in Intel High Level Synthesis Compiler software prior to version 23.4, which may allow an authenticated user with local access to execute code or escalate their privileges. This issue poses significant security risks for systems utilizing affected versions of the compiler, enabling potential exploitation scenarios that could compromise system integrity and confidentiality. Users are advised to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Intel(R) High Level Synthesis Compiler software before version 23.4
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved