Lucene search

K
cveIntelCVE-2023-32618
HistoryFeb 14, 2024 - 2:15 p.m.

CVE-2023-32618

2024-02-1414:15:51
CWE-427
intel
web.nvd.nist.gov
11
cve-2023-32618
intel
oneapi toolkit
security vulnerability
privilege escalation

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Uncontrolled search path in some Intel® oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected configurations

Vulnrichment
Node
inteladvisor
OR
intelinspector
OR
inteloneapi_ai_analytics_toolkit
OR
inteloneapi_base_toolkit
OR
inteloneapi_deep_neural_network
OR
inteloneapi_hpc_toolkit
OR
inteloneapi_iot_toolkit
VendorProductVersionCPE
inteladvisor*cpe:2.3:a:intel:advisor:*:*:*:*:*:*:*:*
intelinspector*cpe:2.3:a:intel:inspector:*:*:*:*:*:*:*:*
inteloneapi_ai_analytics_toolkit*cpe:2.3:a:intel:oneapi_ai_analytics_toolkit:*:*:*:*:*:*:*:*
inteloneapi_base_toolkit*cpe:2.3:a:intel:oneapi_base_toolkit:*:*:*:*:*:*:*:*
inteloneapi_deep_neural_network*cpe:2.3:a:intel:oneapi_deep_neural_network:*:*:*:*:*:*:*:*
inteloneapi_hpc_toolkit*cpe:2.3:a:intel:oneapi_hpc_toolkit:*:*:*:*:*:*:*:*
inteloneapi_iot_toolkit*cpe:2.3:a:intel:oneapi_iot_toolkit:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) oneAPI Toolkit and component software installers",
    "versions": [
      {
        "version": "before version 4.3.2",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Related for CVE-2023-32618