CVE-2023-22440 — Incorrect Default Permissions in Intel Setup AND Configuration Software
Severity
7.8HIGHNVD
CNA6.7
EPSS
0.1%
top 78.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 10
Description
Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages1 packages
🔴Vulnerability Details
2CVEList▶
CVE-2023-22440: Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potenti↗2023-05-10
GHSA▶
GHSA-2r87-2697-cjpc: Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potenti↗2023-05-10