7.8

CVE-2021-0082

Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

Data is provided by the National Vulnerability Database (NVD)
IntelAx210 Firmware Version < 22.40
   IntelAx210 Version-
IntelAx201 Firmware Version < 22.40
   IntelAx201 Version-
IntelAx200 Firmware Version < 22.40
   IntelAx200 Version-
IntelAc 9560 Firmware Version < 22.40
   IntelAc 9560 Version-
IntelAc 9462 Firmware Version < 22.40
   IntelAc 9462 Version-
IntelAc 9461 Firmware Version < 22.40
   IntelAc 9461 Version-
IntelAc 9260 Firmware Version < 22.40
   IntelAc 9260 Version-
IntelAc 8265 Firmware Version < 22.40
   IntelAc 8265 Version-
IntelAc 8260 Firmware Version < 22.40
   IntelAc 8260 Version-
IntelAc 3168 Firmware Version < 22.40
   IntelAc 3168 Version-
Intel7265 Firmware Version < 22.40
   Intel7265 Version-
IntelAc 3165 Firmware Version < 22.40
   IntelAc 3165 Version-
IntelAx1675 Firmware Version < 2.4.1541
   IntelAx1675 Version-
IntelAx1650 Firmware Version < 2.4.1541
   IntelAx1650 Version-
IntelAc1550 Firmware Version < 2.4.1541
   IntelAc1550 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.222
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.