CVE-2024-36245

CWE-4273 documents3 sources
Severity
5.4MEDIUM
EPSS
0.1%
top 75.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13

Description

Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages4 packages

CVEListV5intel(r)_vtune(tm)_profiler_softwarebefore version 2024.2.0
NVDintel/vtune_profiler< 2024.2

🔴Vulnerability Details

2
GHSA
GHSA-gcv7-3w7r-7v38: Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 20242024-11-13
CVEList
CVE-2024-36245: Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 20242024-11-13
CVE-2024-36245 (MEDIUM CVSS 5.4) | Uncontrolled search path element in | cvebase.io