CVE-2021-33094: High severity intel nuc m15 laptop kit vulnerability
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-33094.
What is the title of this vulnerability?
The title of this vulnerability is 'Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Ser…'.
What is the description of this vulnerability?
The description of this vulnerability is 'Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.'
What is the severity of CVE-2021-33094?
The severity of CVE-2021-33094 is high with a CVSS score of 7.8.
How can an authenticated user potentially enable escalation of privilege via local access in this vulnerability?
An authenticated user may be able to enable escalation of privilege via local access by exploiting the insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4.