Intel Driver Support Assistant vulnerabilities
25 known vulnerabilities affecting intel/driver_support_assistant.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH16MEDIUM8
Vulnerabilities
Page 1 of 2
CVE-2023-27515P3CRITICALCVSS 9.6fixed in 23.1.92023-08-11
CVE-2023-27515 [CRITICAL] CWE-79 CVE-2023-27515: Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthentic
Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access.
nvd
CVE-2023-42099P3HIGHCVSS 7.8v23.3.25.62024-05-03
CVE-2023-42099 [HIGH] CWE-59 CVE-2023-42099: Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulne
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
T
nvd
CVE-2023-50197P3HIGHCVSS 7.8v23.3.25.62024-05-03
CVE-2023-50197 [HIGH] CWE-59 CVE-2023-50197: Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulne
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
T
nvd
CVE-2022-26017P3HIGHCVSS 8.0fixed in 22.2.142022-08-18
CVE-2022-26017 [HIGH] CVE-2022-26017: Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authent
Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
nvd
CVE-2021-0094P3HIGHCVSS 7.8fixed in 20.11.50.92021-06-09
CVE-2021-0094 [HIGH] CWE-59 CVE-2021-0094: Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an a
Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.
nvd
CVE-2024-36488P3HIGHCVSS 7.8fixed in 24.3.26.82024-11-13
CVE-2024-36488 [HIGH] CWE-284 CVE-2024-36488: Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated use
Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2024-36294P3HIGHCVSS 7.8fixed in 24.3.26.82024-11-13
CVE-2024-36294 [HIGH] CWE-277 CVE-2024-36294: Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2018-12148P3HIGHCVSS 7.8fixed in 3.5.0.12018-09-12
CVE-2018-12148 [HIGH] CWE-732 CVE-2018-12148: Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may al
Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access.
nvd
CVE-2021-0073P3HIGHCVSS 7.8fixed in 20.11.50.92021-06-09
CVE-2021-0073 [HIGH] CVE-2021-0073: Insufficient control flow management in Intel(R) DSA before version 20.11.50.9 may allow an authenti
Insufficient control flow management in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-30530P3HIGHCVSS 7.8fixed in 22.4.262023-02-16
CVE-2022-30530 [HIGH] CVE-2022-30530: Protection mechanism failure in the Intel(R) DSA software before version 22.4.26 may allow an authen
Protection mechanism failure in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2023-39425P3HIGHCVSS 7.8fixed in 23.4.332024-02-14
CVE-2023-39425 [HIGH] CWE-284 CVE-2023-39425: Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authentica
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-11146P4HIGHCVSS 7.8fixed in 19.7.30.22019-08-19
CVE-2019-11146 [HIGH] CWE-275 CVE-2019-11146: Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authen
Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-11145P4HIGHCVSS 7.8fixed in 19.7.30.22019-08-19
CVE-2019-11145 [HIGH] CWE-275 CVE-2019-11145: Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authen
Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2020-12302P4HIGHCVSS 7.8fixed in 20.7.26.72020-10-05
CVE-2020-12302 [HIGH] CWE-732 CVE-2020-12302: Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow a
Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2023-45743P4HIGHCVSS 7.3fixed in 23.4.39.102024-05-16
CVE-2023-45743 [HIGH] CWE-427 CVE-2023-45743: Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may al
Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2021-0090P4HIGHCVSS 7.3fixed in 20.11.50.92021-06-09
CVE-2021-0090 [HIGH] CWE-427 CVE-2021-0090: Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticate
Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.
nvd
CVE-2022-32764P4HIGHCVSS 7.0fixed in 22.4.262023-02-16
CVE-2022-32764 [HIGH] CWE-362 CVE-2022-32764: Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authent
Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2023-35062P4MEDIUMCVSS 6.7fixed in 23.4.332024-02-14
CVE-2023-35062 [MEDIUM] CWE-284 CVE-2023-35062: Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2018-3621P4MEDIUMCVSS 6.5fixed in 3.6.0.42018-11-14
CVE-2018-3621 [MEDIUM] CWE-200 CVE-2018-3621: Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an un
Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
nvd
CVE-2018-3610P4MEDIUMCVSS 6.0fixed in 3.1.12018-01-09
CVE-2018-3610 [MEDIUM] CWE-119 CVE-2018-3610: SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the a
SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and writing to Memory Status registers potentially allowing information disclosure or a denial of service condition.
nvd
1 / 2Next →