CVE-2023-32660: High severity intel thunderbolt 3 controller firmware vulnerability
Uncontrolled search path in some Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-32660.
What is the title of this vulnerability?
The title of this vulnerability is 'Uncontrolled search path in some Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool i…'.
What is the description of this vulnerability?
The description of this vulnerability is 'Uncontrolled search path in some Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46 may allow an authenticated user to potentially enable escalation of privilege via local access.'
What software is affected by this vulnerability?
The Intel Thunderbolt 3 Controller Firmware before version 46 is affected by this vulnerability.
What is the severity of this vulnerability?
The severity of this vulnerability is high with a CVSS score of 7.3.