Uncontrolled Search Path Vulnerability in Intel VTune Profiler Software
CVE-2024-29015

7.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 August 2024

Summary

A vulnerability exists in Intel's VTune Profiler software where an uncontrolled search path may allow an authenticated user to exploit the system, potentially enabling escalation of privileges through local access. This issue affects versions released before 2024.1 and poses significant security risks for users relying on this software for performance analysis. Organizations utilizing Intel VTune Profiler should assess their deployment and consider measures to mitigate the effects of this vulnerability to safeguard sensitive data and maintain system integrity.

Affected Version(s)

Intel(R) VTune(TM) Profiler software before versions 2024.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.