CVE-2023-27391
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected (29)
Products: Intel: Advisor For Oneapi, Cpu Runtime For Opencl Applications, Distribution For Python Programming Language, Dpc++ Compatibility Tool, Embree Ray Tracing Kernel Library, Fortran Compiler, Implicit Spmd Program Compiler, Inspector For Oneapi, Integrated Performance Primitives, Ipp Cryptography, Mpi Library, Oneapi Base Toolkit, Oneapi Data Analytics Library, Oneapi Deep Neural Network Library, Oneapi Dpc++/c++ Compiler, Oneapi Dpc++ Library (onedpl), Oneapi Hpc Toolkit, Oneapi Iot Toolkit, Oneapi Math Kernel Library, Oneapi Rendering Toolkit, Oneapi Threading Building Blocks, Oneapi Toolkit And Component Software Installer, Oneapi Video Processing Library, Open Image Denoise, Open Volume Kernel Library, Ospray, Ospray Studio, Trace Analyzer And Collector, Vtune Profiler For Oneapi
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 1.19.1 | |
| Before 2023.1 | |
| Before 2021.8 | |
| Before 2021.7.0 | |
| Before 2021.9.0 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2022.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2021.9.0 | |
| Before 4.3.1.493 | |
| Before 2023.1 | |
| Before 1.4.3 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2023.1 | |
| Before 2021.9.0 | |
| Before 2023.1 |
References (2)
Source: secure@intel.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.