7.3

CVE-2023-28823

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Advisor For Oneapi Version < 2023.1
Intel ≫ Dpc++ Compatibility Tool Version < 2023.1
Intel ≫ Fortran Compiler Version < 2023.1
Intel ≫ Inspector For Oneapi Version < 2023.1
Intel ≫ Ipp Cryptography Version < 2021.7.0
Intel ≫ Mpi Library Version < 2021.9.0
Intel ≫ Oneapi Base Toolkit Version < 2023.1
Intel ≫ Oneapi Data Analytics Library Version < 2023.1
Intel ≫ Oneapi Dpc++/c++ Compiler Version < 2023.1
Intel ≫ Oneapi Dpc++ Library (onedpl) Version < 2022.1
Intel ≫ Oneapi Hpc Toolkit Version < 2023.1
Intel ≫ Oneapi Iot Toolkit Version < 2023.1
Intel ≫ Oneapi Math Kernel Library Version < 2023.1
Intel ≫ Oneapi Rendering Toolkit Version < 2023.1
Intel ≫ Oneapi Threading Building Blocks Version < 2021.9.0
Intel ≫ Open Image Denoise Version < 1.4.3
Intel ≫ Open Volume Kernel Library Version < 2023.1
Intel ≫ Ospray Version < 2023.1
Intel ≫ Ospray Studio Version < 2023.1
Intel ≫ Trace Analyzer And Collector Version < 2021.9.0
Intel ≫ Vtune Profiler For Oneapi Version < 2023.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.065
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Intel 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.html
Vendor Advisory