Lucene search

K
cveIntelCVE-2023-28385
HistoryAug 11, 2023 - 3:15 a.m.

CVE-2023-28385

2023-08-1103:15:24
CWE-285
intel
web.nvd.nist.gov
22
cve-2023-28385
intel
nuc
pro software suite
windows
authorization
privilege escalation
security vulnerability

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Improper authorization in the Intelยฎ NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access.

Affected configurations

Nvd
Vulners
Node
intelnext_unit_of_computing_firmwareRange<2.0.0.9
AND
microsoftwindowsMatch-
VendorProductVersionCPE
intelnext_unit_of_computing_firmware*cpe:2.3:o:intel:next_unit_of_computing_firmware:*:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) NUC Pro Software Suite for Windows",
    "versions": [
      {
        "version": "before version 2.0.0.9",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Related for CVE-2023-28385