Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-28172


Uncontrolled search path for some Intel(R) Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.


Published

2024-08-14T14:15:25.280

Last Modified

2024-09-06T18:36:10.863

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-427
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application intel oneapi_hpc_toolkit < 2024.1.0 Yes
Application intel trace_analyzer_and_collector < 2022.1 Yes

References