CVE-2023-42099: (0Day) Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the DSA Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21846.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42099?
CVE-2023-42099 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2023-42099?
To fix CVE-2023-42099, update the Intel Driver & Support Assistant to the latest version provided by Intel.
What systems are affected by CVE-2023-42099?
CVE-2023-42099 affects installations of the Intel Driver & Support Assistant software.
What are the potential impacts of CVE-2023-42099?
Exploitation of CVE-2023-42099 could allow local attackers to escalate their privileges on affected systems.
Is there a known exploit for CVE-2023-42099?
There is no public information confirming an active exploit for CVE-2023-42099 as of now.