First published: Wed May 10 2023(Updated: )
Incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870 may allow an authenticated user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Unite | <4.2.34870 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-33963.
The title of the vulnerability is 'Incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows'.
The vulnerability involves incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870, which may allow an authenticated user to potentially enable escalation of privilege via local access.
The severity of the vulnerability is high with a CVSS score of 7.8.
The Intel Unite(R) Client software for Windows versions before 4.2.34870 are affected.
An authenticated user with local access can potentially enable escalation of privilege.
Yes, upgrading to Intel Unite(R) Client software version 4.2.34870 or later will fix the vulnerability.
More information about the vulnerability can be found at the following link: [https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00782.html](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00782.html)
The Common Weakness Enumeration (CWE) ID for the vulnerability is CWE-276.