Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
References
Link | Resource |
---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00925.html | Patch Vendor Advisory |
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00925.html | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 07:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00925.html - Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
28 Nov 2023, 16:56
Type | Values Removed | Values Added |
---|---|---|
First Time |
Intel server Configuration Utility
Intel |
|
CWE | CWE-428 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
References | () https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00925.html - Patch, Vendor Advisory | |
CPE | cpe:2.3:a:intel:server_configuration_utility:*:*:*:*:*:*:*:* |
14 Nov 2023, 19:30
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-14 19:15
Updated : 2024-11-21 07:49
NVD link : CVE-2023-25075
Mitre link : CVE-2023-25075
CVE.ORG link : CVE-2023-25075
JSON object : View
Products Affected
intel
- server_configuration_utility
CWE
CWE-428
Unquoted Search Path or Element