CVE-2024-21864
7.8
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H
Exploitability: 1.2 / Impact: 6.0
Source: secure@intel.com (Secondary)
Description
Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.
Related CWEs
CWE-707
Improper Neutralization
The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.
CWE-86
Improper Neutralization of Invalid Characters in Identifiers in Web Pages
The product does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.
References (2)
Source: secure@intel.com
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.