CVE-2023-23910

Severity
7.8HIGH
EPSS
0.1%
top 80.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 10

Description

Out-of-bounds write for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:LExploitability: 1.3 | Impact: 2.5

Affected Packages3 packages

CVEListV5intel(r)_trace_analyzer_and_collector_softwarebefore version 2021.8.0 published Dec 2022
NVDintel/oneapi_hpc_toolkit< 2023.0.0

🔴Vulnerability Details

2
CVEList
CVE-2023-23910: Out-of-bounds write for some Intel(R) Trace Analyzer and Collector software before version 20212023-05-10
GHSA
GHSA-rx72-cj6w-pqrg: Out-of-bounds write for some Intel(R) Trace Analyzer and Collector software before version 20212023-05-10
CVE-2023-23910 (HIGH CVSS 7.8) | Out-of-bounds write for some Intel( | cvebase.io