CVE-2022-25864: High severity intel oneapi math kernel library vulnerability
Published Aug 11, 2023
·Updated
Uncontrolled search path in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
1 affected component
Intel oneAPI Math Kernel Library<2022.0
Event History
Aug 11, 2023
CVE Published
via MITRE·02:37 AM
Data Sourced
via MITRE·02:37 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-25864?
The severity of CVE-2022-25864 is high with a CVSS score of 7.8.
2
Which software versions are affected by CVE-2022-25864?
The Intel oneMKL software versions before 2022.0 are affected by CVE-2022-25864.
3
How does CVE-2022-25864 potentially enable escalation of privilege?
CVE-2022-25864 may allow an authenticated user to potentially enable escalation of privilege via local access due to an uncontrolled search path.
4
Is there a fix available for CVE-2022-25864?
Yes, upgrading to version 2022.0 or later of the Intel oneMKL software will fix CVE-2022-25864.
5
Where can I find more information about CVE-2022-25864?
You can find more information about CVE-2022-25864 in [this advisory](http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00873.html).