CVE-2023-32278
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.3 / Impact: 5.9
Source: NVD
Description
Path transversal in some Intel(R) NUC Uniwill Service Driver for Intel(R) NUC M15 Laptop Kits - LAPRC510 & LAPRC710 Uniwill Service Driver installation software before version 1.0.1.7 for Intel(R) NUC Software Studio may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected (1)
Products: Intel: Nuc Uniwill Service Driver
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.7 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc M15 Laptop Kit Evo Laprc510 | All versions |
Intel Nuc M15 Laptop Kit Evo Laprc710 | All versions |
Intel Nuc M15 Laptop Kit Laprc510 | All versions |
Intel Nuc M15 Laptop Kit Laprc710 | All versions |
Related CWEs
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-249
DEPRECATED: Often Misused: Path Manipulation
This entry has been deprecated because of name
confusion and an accidental combination of multiple
weaknesses. Most of its content has been transferred to
CWE-785.
References (2)
Source: secure@intel.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.