CVE-2019-0171Incorrect Permission Assignment in Intel Quartus II

Severity
7.8HIGHNVD
EPSS
0.0%
top 88.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 24

Description

Improper directory permissions in the installer for Intel(R) Quartus(R) software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDintel/quartus_ii9.115.0
NVDintel/quartus_prime15.118.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cxp7-xfhm-mq37: Improper directory permissions in the installer for Intel(R) Quartus(R) software may allow an authenticated user to potentially enable escalation of p2022-05-24
CVEList
CVE-2019-0171: Improper directory permissions in the installer for Intel(R) Quartus(R) software may allow an authenticated user to potentially enable escalation of p2019-05-17
CVE-2019-0171 — Incorrect Permission Assignment | cvebase