7.8

CVE-2023-22355

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Advisor SwPlatform oneapi Version < 2023.0
Intel ≫ Cpu Runtime SwPlatform opencl Version < 2023.0
Intel ≫ Distribution For Python Version < 2023.0
Intel ≫ Dpc++ Compatibility Tool Version < 2023.0
Intel ≫ Fortran Compiler Version < 2023.0
Intel ≫ Inspector SwPlatform oneapi Version < 2023.0
Intel ≫ Mpi Library Version < 2021.8
Intel ≫ Oneapi Base Toolkit Version < 2023.0
Intel ≫ Oneapi Data Analytics Library Version < 2023.0
Intel ≫ Oneapi Dpc++/c++ Compiler Version < 2023.0
Intel ≫ Oneapi Dpc++ Library Version < 2022.0
Intel ≫ Oneapi Hpc Toolkit Version < 2023.0.0
Intel ≫ Oneapi Hpc Toolkit Version 2023.0.0
Intel ≫ Oneapi Iot Toolkit Version < 2023.0
Intel ≫ Oneapi Math Kernel Library Version < 2023.0
Intel ≫ Oneapi Rendering Toolkit Version < 2023.0
Intel ≫ Open Image Denoise Version < 1.4.3
Intel ≫ Open Volume Kernel Library Version < 2023.0
Intel ≫ Ospray Version < 2023.0
Intel ≫ Ospray Studio Version < 2023.0
Intel ≫ Trace Analyzer And Collector Version < 2021.8.0
Intel ≫ Vtune Profiler Version < 2023.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.11
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Intel 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00819.html
Vendor Advisory