CVE-2021-0104

CWE-4274 documents4 sources
Severity
7.8HIGH
EPSS
0.5%
top 32.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 24

Description

Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17.9.0.34, 18.0.0.640 and 18.1.0.24, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDintel/rapid_storage_technology18.0.0.64018.0.3.1148.4+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f4ff-8cq5-xhf7: Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 172022-05-24
CVEList
CVE-2021-0104: Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 172021-06-09

📋Vendor Advisories

1
Chrome
Stable Channel Update for Desktop: CVE-2022-01032022-01-04